Skip to content

Carry the Restart permission patch and publish Core at 2.3.3-azscep.3 - #1

Merged
AzScep merged 3 commits into
azscep/2.3.xfrom
azscep/restart-permission
Sep 26, 2026
Merged

AzScep merged 3 commits into
azscep/2.3.xfrom
azscep/restart-permission

Conversation

@AzScep

@AzScep AzScep commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Implements AzScep/deployment-script#105 (ADR 0003).

  • Carries the Restart specific permission patch (proposed upstream in Add a Restart specific permission for RestartStack聽moghtech/komodo#1650): a user with Read + Restart on a Stack can run RestartStack; every other stack execution still needs Execute and UpdateStack still needs Write.
  • Regenerates ui/public/schema/resources.json.
  • azscep-images.yml (renamed from azscep-periphery-image.yml) now tests the client, Core and Periphery, runs the tests on pull requests into azscep/*.x without publishing, and publishes both ghcr.io/azscep/komodo-core and ghcr.io/azscep/komodo-periphery at 2.3.3-azscep.3.
  • PATCHES.md lists the patch and both images.

Verified end to end against a local Mongo + Core (this branch) + Periphery setup: Read + Logs + Restart restarts and reads logs, and is refused Deploy, Stop, Destroy, Start, Pause, Pull and UpdateStack; Read + Logs is still refused restart; Execute still restarts.

馃 Generated with Claude Code

RestartStack, StopStack, DeployStack and DestroyStack all required the
Execute level, so a user who should only restart a stack could also stop,
destroy, or redeploy it.

- Add `SpecificPermission::Restart`. A user with Read and Restart on a
  Stack can run RestartStack; every other execution still requires
  Execute, and UpdateStack still requires Write. Like other specific
  permissions, Restart on a Server is inherited by its Stacks.
- Add `get_check_any_permissions` (and `setup_stack_execution_any`), which
  pass when the user fulfils any one of several permission sets.
  `get_check_permissions` delegates to it and keeps its error message.
- Compose executions declare their allowed permissions through
  `ExecuteCompose::allowed_permissions`, defaulting to Execute.
- Offer Restart for Stacks in the UI permission selector and document it.

Users without Restart see no change.
Picks up the Restart specific permission and upstream fields the checked-in
schema had missed.
The Restart permission patches Core, so the fork now publishes Core (with
the UI) as well as Periphery, tests the client and Core, and runs the tests
on pull requests into the release branch without publishing.
@AzScep
AzScep force-pushed the azscep/restart-permission branch from 2eed1db to e34cf2a Compare September 26, 2026 11:21
@AzScep AzScep changed the title Carry the Restart permission patch and publish Core at 2.3.3-azscep.2 Carry the Restart permission patch and publish Core at 2.3.3-azscep.3 Sep 26, 2026
@AzScep
AzScep merged commit e044bc1 into azscep/2.3.x Sep 26, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant