Repository navigation
Carry the Restart permission patch and publish Core at 2.3.3-azscep.3 - #1
Merged
Merged
Conversation
RestartStack, StopStack, DeployStack and DestroyStack all required the Execute level, so a user who should only restart a stack could also stop, destroy, or redeploy it. - Add `SpecificPermission::Restart`. A user with Read and Restart on a Stack can run RestartStack; every other execution still requires Execute, and UpdateStack still requires Write. Like other specific permissions, Restart on a Server is inherited by its Stacks. - Add `get_check_any_permissions` (and `setup_stack_execution_any`), which pass when the user fulfils any one of several permission sets. `get_check_permissions` delegates to it and keeps its error message. - Compose executions declare their allowed permissions through `ExecuteCompose::allowed_permissions`, defaulting to Execute. - Offer Restart for Stacks in the UI permission selector and document it. Users without Restart see no change.
Picks up the Restart specific permission and upstream fields the checked-in schema had missed.
The Restart permission patches Core, so the fork now publishes Core (with the UI) as well as Periphery, tests the client and Core, and runs the tests on pull requests into the release branch without publishing.
AzScep
force-pushed
the
azscep/restart-permission
branch
from
September 26, 2026 11:21
2eed1db to
e34cf2a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements AzScep/deployment-script#105 (ADR 0003).
Restartspecific permission patch (proposed upstream in Add a Restart specific permission for RestartStack聽moghtech/komodo#1650): a user with Read + Restart on a Stack can runRestartStack; every other stack execution still needs Execute andUpdateStackstill needs Write.ui/public/schema/resources.json.azscep-images.yml(renamed fromazscep-periphery-image.yml) now tests the client, Core and Periphery, runs the tests on pull requests intoazscep/*.xwithout publishing, and publishes bothghcr.io/azscep/komodo-coreandghcr.io/azscep/komodo-peripheryat2.3.3-azscep.3.PATCHES.mdlists the patch and both images.Verified end to end against a local Mongo + Core (this branch) + Periphery setup: Read + Logs + Restart restarts and reads logs, and is refused Deploy, Stop, Destroy, Start, Pause, Pull and UpdateStack; Read + Logs is still refused restart; Execute still restarts.
馃 Generated with Claude Code