Skip to main content

permission.proto

path mgmt/v1alpha1/permission.proto

package mgmt.v1alpha1


Messages​

ProcedurePermissions​

What a scoped API key must be granted to call a procedure.

NameTypeDescription
all_ofrepeated PermissionThe key needs every one of these.
noneboolThe procedure needs no permission: it tells the caller about itself, or about the deployment, and holds nothing a scope restricts. Set only when that is true — a procedure with neither this nor a permission is refused to every scoped key.

Enums​

Permission​

A permission a caller can be granted: one action on one kind of entity, as the RBAC names them. An API key's scope is a list of these, and can only narrow what the key may do.

NameNumberDescription
PERMISSION_UNSPECIFIED0
PERMISSION_ACCOUNT_VIEW1
PERMISSION_ACCOUNT_EDIT2
PERMISSION_ACCOUNT_CREATE3
PERMISSION_ACCOUNT_DELETE4
PERMISSION_CONNECTION_VIEW5
PERMISSION_CONNECTION_VIEW_SENSITIVE6Holding a connection's secrets: seeing them in clear, and using the connection — reading its schema, scanning or previewing its data — which takes them. Without it, a connection comes back masked, and cannot be connected to.
PERMISSION_CONNECTION_CREATE7
PERMISSION_CONNECTION_EDIT8
PERMISSION_CONNECTION_DELETE9
PERMISSION_JOB_VIEW10
PERMISSION_JOB_CREATE11
PERMISSION_JOB_EDIT12
PERMISSION_JOB_EXECUTE13Running a job, which writes to a real destination — and anything that makes it run: creating it with a first run or an active schedule, setting its schedule, resuming it, writing or enabling one of its SQL hooks.
PERMISSION_JOB_DELETE14