Permissions Reference¶
This page provides a comprehensive reference of all available permissions in edgeContinuum. Permissions are used to control what users and groups can do within the platform and are organized by service and resource type.
Understanding Permissions¶
edgeContinuum uses a relationship-based access control (ReBAC) model where:
- Permissions are granted through role bindings that connect users or groups to roles
- Roles are collections of permissions that can be assigned at organization or project level
- Organization-level permissions can inherit to projects within that organization (marked with ✓ in the Inheritable column)
- Project-level permissions apply only to that specific project
In the console you assign permissions directly
Although access is modeled with roles and role bindings underneath, the console lets you grant access by selecting permissions for a user or group at a given scope. The platform manages the corresponding roles for you, so you do not create or name roles yourself in the UI.
Scope Levels¶
- Org: Permission can be granted at the organization level (may inherit to projects)
- Project: Permission can be granted at the project level (applies only to that project)
- Org/Project: Permission can be granted at either level
Permission Implication¶
Some permissions are implied by a broader one. When a permission lists a parent in the Implied by column of the tables below, everyone who holds that parent automatically holds the child as well — you do not have to grant it separately.
For example, mvms_update implies the fine-grained virtual machine operations:
mvms_update
├─ mvms_power_update (power on/off, reboot)
├─ mvms_resize_update (resize)
├─ mvms_network_attachment_update (attach/detach NICs)
├─ mvms_monitoring_update (metrics on/off)
├─ mvms_metadata_update (rename, description)
└─ mvms_action_update (cancel/sync operations)
This gives you two ways to grant the same capability:
- Coarse: grant
mvms_updateto someone who should be able to change virtual machines in any way - Fine: grant only
mvms_power_updateto someone who should be able to reboot a virtual machine but never resize it or touch its network
The same split applies to reads: every <resource>_get permission is a read bundle that implies a <resource>_metadata_get child covering only the plain "view details" endpoints — metadata, dependents, sharing information and action listings — alongside the children that hand out credentials or telemetry. Writes mirror it with a <resource>_metadata_update child that covers only renaming a resource or editing its description.
mks_get
├─ mks_metadata_get (cluster details, dependents, action listings)
├─ mks_kubeconfig_get (kubeconfig download, carries credentials)
└─ mks_metrics_get (cluster and node metrics)
Grant mks_metadata_get on its own when someone needs credential-free visibility: they can see the cluster and inspect its configuration, but cannot download its kubeconfig.
Implication only ever flows downwards, from parent to child. Holding a child permission never grants its parent or its siblings, so the fine-grained permissions are safe to hand out on their own.
Start coarse, then narrow
Grant the coarse permission for roles that own a resource end to end, and reach for the fine-grained children when you need to carve out a narrower job, such as an on-call rotation that may reboot virtual machines and read their logs but must not resize or delete them.
Permissions with no entry in the Implied by column stand on their own and must be granted explicitly.
Resource Manager Permissions¶
Resource manager permissions cover identity and access management: organizations, projects, members, groups, permission grants and quota.
Organizations¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_organization_get |
Org | ✗ | — | View organization details |
resourcemanager_organization_update |
Org | ✗ | — | Replace the organization settings |
resourcemanager_organization_patch |
Org | ✗ | — | Partially update the organization settings |
resourcemanager_organization_delete |
Org | ✗ | — | Delete the organization |
Projects¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_project_create |
Org/Project | ✓ | — | Create a project in the organization |
resourcemanager_project_get |
Org/Project | ✓ | — | View project details |
resourcemanager_project_list |
Org/Project | ✓ | — | List projects |
resourcemanager_project_update |
Org/Project | ✓ | — | Replace a project's settings |
resourcemanager_project_patch |
Org/Project | ✓ | — | Partially update a project's settings |
resourcemanager_project_delete |
Org/Project | ✓ | — | Delete a project |
Organization Members¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_organization_member_add |
Org | ✗ | — | Add a user to the organization |
resourcemanager_organization_member_get |
Org | ✗ | — | View an organization member |
resourcemanager_organization_member_list |
Org | ✗ | — | List organization members |
resourcemanager_organization_member_remove |
Org | ✗ | — | Remove a user from the organization |
Groups¶
Groups are defined at the organization level and can then be granted permissions in the organization and in individual projects.
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_group_create |
Org | ✗ | — | Create a group |
resourcemanager_group_get |
Org | ✗ | — | View group details |
resourcemanager_group_list |
Org | ✗ | — | List groups |
resourcemanager_group_update |
Org | ✗ | — | Replace a group's settings |
resourcemanager_group_patch |
Org | ✗ | — | Partially update a group |
resourcemanager_group_delete |
Org | ✗ | — | Delete a group |
resourcemanager_group_user_add |
Org | ✗ | — | Add a user to a group |
resourcemanager_group_user_list |
Org | ✗ | — | List the members of a group |
resourcemanager_group_user_delete |
Org | ✗ | — | Remove a user from a group |
Organization Permission Grants¶
These permissions control who can grant access to others at the organization level. Treat them as administrative: anyone holding them can widen their own team's access.
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_organization_user_role_grant |
Org | ✗ | — | Grant organization-level permissions to a user |
resourcemanager_organization_user_role_revoke |
Org | ✗ | — | Revoke a user's organization-level permissions |
resourcemanager_organization_user_role_update |
Org | ✗ | — | Change the organization-level permissions granted to a user |
resourcemanager_organization_user_role_get |
Org | ✗ | — | View the organization-level permissions granted to a user |
resourcemanager_organization_user_role_list |
Org | ✗ | — | List the organization-level permission grants of all users |
resourcemanager_organization_group_role_grant |
Org | ✗ | — | Grant organization-level permissions to a group |
resourcemanager_organization_group_role_revoke |
Org | ✗ | — | Revoke a group's organization-level permissions |
resourcemanager_organization_group_role_update |
Org | ✗ | — | Change the organization-level permissions granted to a group |
resourcemanager_organization_group_role_get |
Org | ✗ | — | View the organization-level permissions granted to a group |
resourcemanager_organization_group_role_list |
Org | ✗ | — | List the organization-level permission grants of all groups |
Project Permission Grants¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_project_user_role_grant |
Org/Project | ✓ | — | Grant project permissions to a user |
resourcemanager_project_user_role_revoke |
Org/Project | ✓ | — | Revoke a user's project permissions |
resourcemanager_project_user_role_update |
Org/Project | ✓ | — | Change the project permissions granted to a user |
resourcemanager_project_user_role_get |
Org/Project | ✓ | — | View the project permissions granted to a user |
resourcemanager_project_user_role_list |
Org/Project | ✓ | — | List the project permission grants of all users |
resourcemanager_project_group_role_grant |
Org/Project | ✓ | — | Grant project permissions to a group |
resourcemanager_project_group_role_revoke |
Org/Project | ✓ | — | Revoke a group's project permissions |
resourcemanager_project_group_role_update |
Org/Project | ✓ | — | Change the project permissions granted to a group |
resourcemanager_project_group_role_get |
Org/Project | ✓ | — | View the project permissions granted to a group |
resourcemanager_project_group_role_list |
Org/Project | ✓ | — | List the project permission grants of all groups |
Quota¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_organization_quota_get |
Org | ✗ | — | View the organization's quota limits and current usage |
resourcemanager_organization_quota_profile_get |
Org | ✗ | — | View the organization's quota profile |
resourcemanager_organization_quota_profile_register |
Org | ✗ | — | Register a quota profile for the organization |
resourcemanager_organization_quota_profile_update |
Org | ✗ | — | Update the organization's quota profile |
resourcemanager_organization_quota_profile_deregister |
Org | ✗ | — | Deregister the organization's quota profile |
Infrastructure Permissions¶
Infrastructure permissions cover the physical and provider-side layer of the platform: regions, zones, infrastructures, their image and flavor catalogs, and the service configs that back managed services.
Regions¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
region_create |
Org | ✗ | — | Create a region |
region_get |
Org | ✗ | — | Full read access to a region. Implies region_metadata_get |
region_list |
Org | ✗ | — | List regions |
region_update |
Org | ✗ | — | Update a region. Implies region_metadata_update |
region_delete |
Org | ✗ | — | Delete a region |
region_metadata_get |
Org | ✗ | region_get |
Read the plain region details: metadata, dependents and action listings |
region_metadata_update |
Org | ✗ | region_update |
Rename a region or edit its description |
Zones¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
zone_create |
Org | ✗ | — | Create a zone |
zone_get |
Org | ✗ | — | Full read access to a zone. Implies zone_metadata_get |
zone_list |
Org | ✗ | — | List zones |
zone_update |
Org | ✗ | — | Update a zone. Implies zone_metadata_update |
zone_delete |
Org | ✗ | — | Delete a zone |
zone_metadata_get |
Org | ✗ | zone_get |
Read the plain zone details: metadata, dependents and action listings |
zone_metadata_update |
Org | ✗ | zone_update |
Rename a zone or edit its description |
Infrastructures¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
infra_create |
Org | ✗ | — | Create an infrastructure |
infra_get |
Org | ✗ | — | Full read access to an infrastructure, including provider discovery and preflight introspection. Implies infra_metadata_get |
infra_list |
Org | ✗ | — | List infrastructures |
infra_update |
Org | ✗ | — | Update an infrastructure. Implies every fine-grained infrastructure permission below, plus the image and flavor catalog permissions |
infra_delete |
Org | ✗ | — | Delete an infrastructure |
infra_metadata_get |
Org | ✗ | infra_get |
Read the plain infrastructure details: metadata, dependents and action listings, without the provider discovery and preflight introspection |
infra_credentials_update |
Org | ✗ | infra_update |
Rotate the credentials used to reach the infrastructure provider |
infra_action_update |
Org | ✗ | infra_update |
Create actions (cancel, sync) on infrastructure operations |
infra_storage_update |
Org | ✗ | infra_update |
Edit the storage configuration: offered volume types and the default volume type |
infra_network_config_update |
Org | ✗ | infra_update |
Edit the network configuration: DNS nameservers and the load balancer provider |
infra_shards_update |
Org | ✗ | infra_update |
Edit which shards may manage the infrastructure |
infra_metadata_update |
Org | ✗ | infra_update |
Rename an infrastructure or edit its description and location |
Images¶
Images are read at organization and project level, because projects need them to create virtual machines and clusters. Changing the catalog is an organization-level infrastructure task.
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
image_get |
Org/Project | ✓ | — | View image details |
image_list |
Org/Project | ✓ | — | List images |
image_import |
Org | ✗ | infra_update |
Import image entries from the provider catalog |
image_update |
Org | ✗ | infra_update |
Patch or delete image catalog entries |
Flavors¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
flavor_get |
Org/Project | ✓ | — | View flavor details |
flavor_list |
Org/Project | ✓ | — | List flavors |
flavor_import |
Org | ✗ | infra_update |
Import flavor entries from the provider catalog |
flavor_update |
Org | ✗ | infra_update |
Patch or delete flavor catalog entries |
Service Configs and Service Platforms¶
Service configs group the service platforms that back managed services on an infrastructure. Managing a config's service platforms (including org-owned managed clusters) is gated by service_config_update.
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
service_config_create |
Org | ✗ | — | Create a service config |
service_config_get |
Org | ✗ | — | Full read access to a service config. Implies service_config_metadata_get |
service_config_list |
Org | ✗ | — | List service configs |
service_config_update |
Org | ✗ | — | Update a service config and manage its service platforms. Implies service_platform_update |
service_config_delete |
Org | ✗ | — | Delete a service config |
service_config_metadata_get |
Org | ✗ | service_config_get |
Read the plain service config details: metadata, dependents and action listings |
service_config_metadata_update |
Org | ✗ | service_config_update |
Rename a service config or edit its description |
service_platform_update |
Org | ✗ | service_config_update |
Manage a service platform. Implies the platform upgrade and enable/disable permissions below |
service_platform_upgrade_update |
Org | ✗ | service_platform_update |
Upgrade a service platform |
service_platform_enabled_update |
Org | ✗ | service_platform_update |
Enable or disable a service platform |
Managed Services Permissions¶
Managed services permissions control access to Kubernetes clusters, virtual machines and PostgreSQL instances. Each service exposes coarse lifecycle permissions plus fine-grained children for individual day-2 operations and for reads that expose credentials or telemetry.
Managed Kubernetes Service (MKS)¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
mks_create |
Org/Project | ✓ | — | Create a Kubernetes cluster |
mks_get |
Org/Project | ✓ | — | Full read access to a cluster. Implies the metadata, kubeconfig and metrics reads below |
mks_list |
Org/Project | ✓ | — | List clusters |
mks_update |
Org/Project | ✓ | — | Update a cluster. Implies every day-2 cluster operation below |
mks_delete |
Org/Project | ✓ | — | Delete a cluster |
mks_metadata_get |
Org/Project | ✓ | mks_get |
Read the plain cluster details: metadata, dependents and action listings, without the kubeconfig |
mks_kubeconfig_get |
Org/Project | ✓ | mks_get |
Download the cluster kubeconfig, which carries cluster credentials |
mks_metrics_get |
Org/Project | ✓ | mks_get |
Read cluster and node metrics |
mks_action_update |
Org/Project | ✓ | mks_update |
Create actions (cancel, sync) on cluster operations |
mks_controlplane_upgrade_update |
Org/Project | ✓ | mks_update |
Upgrade the control plane Kubernetes version |
mks_controlplane_resize_update |
Org/Project | ✓ | mks_update |
Resize the control plane: compute flavor and/or replica count |
mks_csi_update |
Org/Project | ✓ | mks_update |
Manage the cluster CSI (storage) configuration |
mks_nodepool_scale_update |
Org/Project | ✓ | mks_update |
Scale a node pool |
mks_nodepool_upgrade_update |
Org/Project | ✓ | mks_update |
Upgrade a node pool's Kubernetes version |
mks_monitoring_update |
Org/Project | ✓ | mks_update |
Enable or disable the cluster's end-user metrics |
mks_metadata_update |
Org/Project | ✓ | mks_update |
Rename a cluster or edit its description |
Managed VM Service (MVMS)¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
mvms_create |
Org/Project | ✓ | — | Create a virtual machine |
mvms_get |
Org/Project | ✓ | — | Full read access to a VM. Implies the metadata, logs, console and metrics reads below |
mvms_list |
Org/Project | ✓ | — | List virtual machines |
mvms_update |
Org/Project | ✓ | — | Update a VM. Implies every fine-grained VM operation below |
mvms_delete |
Org/Project | ✓ | — | Delete a virtual machine |
mvms_power_update |
Org/Project | ✓ | mvms_update |
Power a VM on or off, and reboot it |
mvms_resize_update |
Org/Project | ✓ | mvms_update |
Resize a VM |
mvms_network_attachment_update |
Org/Project | ✓ | mvms_update |
Attach, detach and modify a VM's network interfaces |
mvms_action_update |
Org/Project | ✓ | mvms_update |
Create actions (cancel, sync) on VM operations |
mvms_monitoring_update |
Org/Project | ✓ | mvms_update |
Enable or disable the VM's end-user metrics |
mvms_metadata_update |
Org/Project | ✓ | mvms_update |
Rename a VM or edit its description |
mvms_metadata_get |
Org/Project | ✓ | mvms_get |
Read the plain VM details: metadata, dependents and action listings, without the console |
mvms_logs_get |
Org/Project | ✓ | mvms_get |
Read VM logs |
mvms_console_get |
Org/Project | ✓ | mvms_get |
Access the VM console |
mvms_metrics_get |
Org/Project | ✓ | mvms_get |
Read VM metrics |
VM Snapshots¶
Snapshots are managed as their own resource, so their permissions are independent of the VM permissions above.
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
mvms_snapshot_create |
Org/Project | ✓ | — | Create a VM snapshot |
mvms_snapshot_get |
Org/Project | ✓ | — | View snapshot details |
mvms_snapshot_list |
Org/Project | ✓ | — | List a VM's snapshots |
mvms_snapshot_update |
Org/Project | ✓ | — | Update a snapshot |
mvms_snapshot_delete |
Org/Project | ✓ | — | Delete a snapshot |
Managed PostgreSQL Service¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
postgresql_instance_create |
Org/Project | ✓ | — | Create a PostgreSQL instance |
postgresql_instance_get |
Org/Project | ✓ | — | Full read access to an instance. Implies the metadata, connection and metrics reads below |
postgresql_instance_list |
Org/Project | ✓ | — | List PostgreSQL instances |
postgresql_instance_update |
Org/Project | ✓ | — | Update an instance. Implies every fine-grained instance operation below |
postgresql_instance_delete |
Org/Project | ✓ | — | Delete a PostgreSQL instance |
postgresql_instance_metadata_get |
Org/Project | ✓ | postgresql_instance_get |
Read the plain instance details: metadata, dependents and action listings, without the connection information |
postgresql_instance_connection_get |
Org/Project | ✓ | postgresql_instance_get |
Read the instance connection information, including database credentials |
postgresql_instance_metrics_get |
Org/Project | ✓ | postgresql_instance_get |
Read instance metrics |
postgresql_instance_action_update |
Org/Project | ✓ | postgresql_instance_update |
Create actions (cancel, sync) on instance operations |
postgresql_instance_resize_update |
Org/Project | ✓ | postgresql_instance_update |
Resize an instance: compute size, storage (grow-only) and high availability |
postgresql_instance_upgrade_update |
Org/Project | ✓ | postgresql_instance_update |
Upgrade the instance's PostgreSQL version |
postgresql_instance_monitoring_update |
Org/Project | ✓ | postgresql_instance_update |
Enable or disable the instance's end-user metrics |
postgresql_instance_metadata_update |
Org/Project | ✓ | postgresql_instance_update |
Rename an instance or edit its description |
Networking Permissions¶
Networking permissions cover the network resources that managed services attach to, plus the SSH keys used to reach virtual machines. Import permissions adopt resources that already exist on the infrastructure provider, and share permissions control whether a resource can be offered to other projects in the organization.
Networks¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
network_create |
Org/Project | ✓ | — | Create a network |
network_get |
Org/Project | ✓ | — | Full read access to a network. Implies network_metadata_get |
network_list |
Org/Project | ✓ | — | List networks |
network_update |
Org/Project | ✓ | — | Update a network. Implies every fine-grained network operation below |
network_delete |
Org/Project | ✓ | — | Delete a network |
network_import |
Org/Project | ✓ | — | Adopt an existing network from the infrastructure provider |
network_share |
Org/Project | ✓ | — | Manage sharing of a network with other projects |
network_metadata_get |
Org/Project | ✓ | network_get |
Read the plain network details: metadata, dependents, sharing information and action listings |
network_action_update |
Org/Project | ✓ | network_update |
Create actions (cancel, sync) on network operations |
network_dhcp_update |
Org/Project | ✓ | network_update |
Edit the network's DHCP configuration (allocation pools, DNS servers, gateway, static routes) |
network_metadata_update |
Org/Project | ✓ | network_update |
Rename a network or edit its description |
Routers¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
router_create |
Org/Project | ✓ | — | Create a router |
router_get |
Org/Project | ✓ | — | Full read access to a router. Implies router_metadata_get |
router_list |
Org/Project | ✓ | — | List routers |
router_update |
Org/Project | ✓ | — | Update a router. Implies every fine-grained router operation below |
router_delete |
Org/Project | ✓ | — | Delete a router |
router_metadata_get |
Org/Project | ✓ | router_get |
Read the plain router details: metadata, dependents and action listings |
router_route_update |
Org/Project | ✓ | router_update |
Manage the routes of a router |
router_network_attachment_update |
Org/Project | ✓ | router_update |
Attach and detach networks on a router |
router_action_update |
Org/Project | ✓ | router_update |
Create actions (cancel, sync) on router operations |
router_metadata_update |
Org/Project | ✓ | router_update |
Rename a router or edit its description |
Firewalls¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
firewall_create |
Org/Project | ✓ | — | Create a firewall |
firewall_get |
Org/Project | ✓ | — | Full read access to a firewall. Implies firewall_metadata_get |
firewall_list |
Org/Project | ✓ | — | List firewalls |
firewall_update |
Org/Project | ✓ | — | Update a firewall. Implies every fine-grained firewall operation below |
firewall_delete |
Org/Project | ✓ | — | Delete a firewall |
firewall_import |
Org/Project | ✓ | — | Adopt an existing firewall from the infrastructure provider |
firewall_share |
Org/Project | ✓ | — | Manage sharing of a firewall with other projects |
firewall_metadata_get |
Org/Project | ✓ | firewall_get |
Read the plain firewall details: metadata, dependents, sharing information and action listings |
firewall_action_update |
Org/Project | ✓ | firewall_update |
Create actions (cancel, sync) on firewall operations |
firewall_rules_update |
Org/Project | ✓ | firewall_update |
Edit the firewall's ruleset |
firewall_metadata_update |
Org/Project | ✓ | firewall_update |
Rename a firewall or edit its description |
SSH Keys¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
sshkey_create |
Org/Project | ✓ | — | Create or upload an SSH key |
sshkey_get |
Org/Project | ✓ | — | Full read access to an SSH key. Implies sshkey_metadata_get |
sshkey_list |
Org/Project | ✓ | — | List SSH keys |
sshkey_update |
Org/Project | ✓ | — | Update an SSH key |
sshkey_delete |
Org/Project | ✓ | — | Delete an SSH key |
sshkey_import |
Org/Project | ✓ | — | Adopt an existing SSH key from the infrastructure provider |
sshkey_share |
Org/Project | ✓ | — | Manage sharing of an SSH key with other projects |
sshkey_attach |
Org/Project | ✓ | — | Attach an SSH key to a VM when creating it |
sshkey_metadata_get |
Org/Project | ✓ | sshkey_get |
Read the plain SSH key details: metadata, dependents, sharing information and action listings |
Application Orchestration Permissions¶
Application orchestration permissions control access to managed application resources through the Edge Orchestrator (MEO).
Application Templates¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
meo_application_template_get |
Org/Project | ✓ | — | View an application template |
meo_application_template_list |
Org/Project | ✓ | — | List application templates |
meo_application_template_create |
Org/Project | ✓ | — | Create an application template |
meo_application_template_update |
Org/Project | ✓ | — | Replace an application template |
meo_application_template_patch |
Org/Project | ✓ | — | Partially update an application template |
meo_application_template_delete |
Org/Project | ✓ | — | Delete an application template |
Application Instances¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
meo_application_instance_get |
Org/Project | ✓ | — | View an application instance |
meo_application_instance_list |
Org/Project | ✓ | — | List application instances |
meo_application_instance_create |
Org/Project | ✓ | — | Create an application instance |
meo_application_instance_update |
Org/Project | ✓ | — | Replace an application instance |
meo_application_instance_patch |
Org/Project | ✓ | — | Partially update an application instance |
meo_application_instance_delete |
Org/Project | ✓ | — | Delete an application instance |
Application Clusters¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
meo_application_cluster_get |
Org/Project | ✓ | — | View an application cluster |
meo_application_cluster_list |
Org/Project | ✓ | — | List application clusters |
meo_application_cluster_create |
Org/Project | ✓ | — | Create an application cluster |
meo_application_cluster_update |
Org/Project | ✓ | — | Replace an application cluster |
meo_application_cluster_patch |
Org/Project | ✓ | — | Partially update an application cluster |
meo_application_cluster_delete |
Org/Project | ✓ | — | Delete an application cluster |
meo_application_cluster_getfleet |
Org/Project | ✓ | — | View the fleet a cluster belongs to |
Cluster Fleets¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
meo_application_clusterfleet_get |
Org/Project | ✓ | — | View a cluster fleet |
meo_application_clusterfleet_list |
Org/Project | ✓ | — | List cluster fleets |
meo_application_clusterfleet_create |
Org/Project | ✓ | — | Create a cluster fleet |
meo_application_clusterfleet_update |
Org/Project | ✓ | — | Replace a cluster fleet |
meo_application_clusterfleet_patch |
Org/Project | ✓ | — | Partially update a cluster fleet |
meo_application_clusterfleet_delete |
Org/Project | ✓ | — | Delete a cluster fleet |
meo_application_clusterfleet_addcluster |
Org/Project | ✓ | — | Add a cluster to a fleet |
meo_application_clusterfleet_removecluster |
Org/Project | ✓ | — | Remove a cluster from a fleet |
Cluster Fleet Instances¶
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
meo_application_clusterfleetinstance_get |
Org/Project | ✓ | — | View a cluster fleet instance |
meo_application_clusterfleetinstance_list |
Org/Project | ✓ | — | List cluster fleet instances |
meo_application_clusterfleetinstance_create |
Org/Project | ✓ | — | Create a cluster fleet instance |
meo_application_clusterfleetinstance_patch |
Org/Project | ✓ | — | Partially update a cluster fleet instance |
meo_application_clusterfleetinstance_delete |
Org/Project | ✓ | — | Delete a cluster fleet instance |
Stats and Billing Permissions¶
These read-only organization permissions back the dashboards and the billing views. They expose aggregate counts and usage, not the resources themselves.
| Permission | Scope | Inheritable | Implied by | Description |
|---|---|---|---|---|
resourcemanager_organization_stats_get |
Org | ✗ | — | Read organization statistics: project, member and group counts |
meo_organization_stats_get |
Org | ✗ | — | Read application orchestration statistics for the organization |
rex_stats_get |
Org | ✗ | — | Read managed-resource statistics for the organization |
billing_usage_get |
Org | ✗ | — | Read the organization's usage and billing data |
Permission Inheritance¶
Some organization-level permissions automatically apply to projects within that organization. This inheritance happens through the authorization model:
How Inheritance Works¶
Organization (acme-corp)
└─ mks_get (inheritable ✓)
├─ Project A (backend-api)
│ └─ Inherits: mks_get
│
└─ Project B (frontend-app)
└─ Inherits: mks_get
When a user or group has an inheritable organization-level permission:
- They automatically have that permission in all projects
- Project-level permissions can still grant or restrict access further
- Permissions are checked through multiple paths: direct project grants, group membership, and organization inheritance
Inheritance and implication are different
Inheritance moves a permission you already hold down the scope hierarchy, from the organization to its projects. Implication derives other permissions from the one you hold, at the same scope. They combine: an inheritable parent granted at the organization level also gives you its implied children in every project.
Permission Resolution¶
When checking if a user can perform an action on a project, the system checks:
- Direct role bindings on the project
- Group memberships and their role bindings on the project
- Organization-level role bindings (inherited permissions)
- Organization-level group role bindings
The user has access if any of these paths grants the required permission.
Special Roles¶
Super Admin¶
The super_admin role has special access:
- Grants all available permissions through
all_permissions - Applies at organization level with full inheritance to projects
- Intended for organization owners and administrators
Best Practices¶
- Use groups for consistency: Assign permissions to groups for common job functions rather than to individual users, for easier management
- Apply least privilege: Grant only the permissions needed for users to perform their work
- Prefer fine-grained permissions for narrow jobs: When a role only needs one operation on a resource, grant the implied child instead of the coarse parent
- Guard credential-bearing reads:
mks_kubeconfig_getandpostgresql_instance_connection_gethand out working credentials, so grant them only where they are needed, and reach for<resource>_metadata_getwhen a role only needs to see the resource - Watch the grant permissions: Anyone who can grant permissions to users or groups can widen access for the whole team, so treat those permissions as administrative
- Plan inheritance: Use organization-level inheritable permissions to establish baseline access, then use project-level permissions for fine-grained control
- Audit regularly: Review who has what permissions to ensure they align with current team structure and responsibilities
- Use meaningful group names: Choose group names that clearly describe their purpose (e.g., "project-viewer", "infrastructure-admin")