Conversation
RestartStack, StopStack, DeployStack and DestroyStack all required the Execute level, so a user who should only restart a stack could also stop, destroy, or redeploy it. - Add `SpecificPermission::Restart`. A user with Read and Restart on a Stack can run RestartStack; every other execution still requires Execute, and UpdateStack still requires Write. Like other specific permissions, Restart on a Server is inherited by its Stacks. - Add `get_check_any_permissions` (and `setup_stack_execution_any`), which pass when the user fulfils any one of several permission sets. `get_check_permissions` delegates to it and keeps its error message. - Compose executions declare their allowed permissions through `ExecuteCompose::allowed_permissions`, defaulting to Execute. - Offer Restart for Stacks in the UI permission selector and document it. Users without Restart see no change.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
RestartStack,StartStack,StopStack,DeployStackandDestroyStackall require theExecutelevel.There is no way to let a user (or a service user driving an automation) restart a stack without also letting it stop, destroy, or redeploy that stack.
A leaked restart-only credential should not be able to take an app down.
Change
SpecificPermission::Restart.A user with
ReadandRestarton a Stack can runRestartStack, including for single services.Every other stack execution still requires
Execute, andUpdateStackstill requiresWrite.Like the other specific permissions,
Restartgiven on a Server is inherited by that server's Stacks.get_check_any_permissions(andsetup_stack_execution_any), which pass when the user fulfils any one of several permission sets.get_check_permissionsnow delegates to it with a single set, and its error message is unchanged.ExecuteComposegainsallowed_permissions(), defaulting toExecute;RestartStackreturns[Execute, Read + Restart].Restartfor Stacks in the UI's specific permission selector, regenerate the TS types, and document it inpermissioning.md.Users without
Restartsee no behaviour change.The UI still shows stack executions only with
Execute, so a restart-only user restarts through the API; happy to follow up with a UI change if you want one.Verification
permission::testsin Core and 2 in the client'sentities::permission(serde round trip and unchanged variant names).Removing
Read + RestartfromRestartStack::allowed_permissionsmakes 2 of the Core tests fail.cargo fmt --checkand clippy clean for the changed files.Read+[Logs, Restart]on a stack restarts it and reads its logs;DeployStack,StopStack,DestroyStack,StartStack,PauseStack,PullStack(the Update completes unsuccessfully with the permission error) andUpdateStack;Read+[Logs]is still refusedRestartStack, a user withExecutestill restarts, andRestartwithoutReadis refused.On upstream 2.3.3 the same script fails at granting
Restart(unknown variant).馃 Generated with Claude Code