Skip to main content
A role is a catalog resource that bundles permissions under a reusable name. Tenant bindings reference roles to grant permissions to users and groups.

Fields

Permission format

Each entry in permissions is a string in one of four forms:

Kinds

A {kind} is any catalog resource type: recipe, image, environment, pool-config, service-profile, repo-config, agent-persona, agent, flight, change-request, workspace, placement, machine-type, disk-type, secret, alias, role, group, tenant-binding, user, user-secret.

Verbs

Examples

Create a role with full agent access

Create a read-only role

Create a role scoped to secrets

Listing roles

Reading a single role

Errors