This repository was archived by the owner on Sep 29, 2026. It is now read-only.
Repository navigation
docs: document Builder, Scorch, and Tunneler permissions and roles - #71
Closed
GhostofGoes wants to merge 3 commits into
Closed
GhostofGoes wants to merge 3 commits into
GhostofGoes wants to merge 3 commits into
Conversation
Document the builder, scorch, scorch/terminals, and tunneler RBAC resources, the new Scorch Viewer, Scorch Admin, and Builder roles, the built-in roles' service access, the upgrade migration, and why typing into Scorch terminals is a separate permission. Also document Kind/name checks for configs, how resource names scope a role, and that users with an unknown role are rejected. The built-in role YAML is copied from phenix. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
7 of 11 tasks
Split the roles, permissions, and built-in role definitions out of the users page into a new Roles and Permissions page under Administration, and review both pages against phenix: - Document how permissions are checked, scoping, custom roles, and every resource and verb phenix checks, including the 21 that were missing. - Fix the auth header format (Bearer <token>), the VITE_AUTH build variable, self sign-up behavior, the token dialog, and the Users dialog fields. - Document both proxy setups, the default admin@foo.com user, ui.users sources and behavior, password requirements, signing in, logout, and token revocation. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Match phenix changes: add the users/tokens resource, note that the configs API never returns User config password hashes or tokens, that live logs need logs get, that captures are filtered by experiment/VM, and that the Experiment Viewer role can mount VM disks. Regenerate the built-in role definitions from phenix. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
tl;dr: Documents the new Builder, Scorch, and Tunneler permissions and roles, and moves roles and permissions to their own page.
Changes
scorch/terminalssecurity warning, and the upgrade migration. The role YAML is copied verbatim from phēnix.This includes the new
users/tokenscreatepermission, and notes that the configs API never returns User config password hashes or tokens.VITE_AUTH, notVUE_APP_AUTH.X-Phenix-Auth-Token: Bearer <token>, not a bare token.Disabledaccount and doesn't notify administrators.users/tokenscreate, and phēnix doesn't show a user's tokens.admin@foo.comuser;ui.userssources, format, precedence, and startup-only behavior; password requirements; signing in, logout, and API login; token revocation; editing and deleting users.breakand Scorch table text follow the new permissions.Background
sandialabs/sceptre-phenix#385 puts the Builder, Scorch, and Tunneler under access control and adds built-in roles, so the permissions docs needed updating. Reviewing the page against the code also showed it was out of date. It had the old UI build variable and a wrong API header format, described sign-up and token behavior that no longer exists, and was missing 21 checked resource/verb pairs.
Related Issues/PRs
Type of Change
fix)feat)docs)refactor)chore)Checklist
Testing
mkdocs build --strictpasses.#anchorlink in every docs page resolves in the rendered HTML (0 broken).prek runpasses on the changed files.src/go/api/config/default.ui.usersbehavior was checked on a running phēnix. Users added to a users file while phēnix is running are not picked up, so the page says the list is read at startup.Additional Notes
Draft until sandialabs/sceptre-phenix#385 settles the default role permissions.
🤖 Generated with Claude Code