Permission
A Permission defines access control rules that grant or deny specific actions to subjects on target objects.
Overview
A Permission has 4 parts:
- Subject: The user or service requesting access
- Object: The resources this permission affects (playbooks, connections, or configs)
- Effect: Whether to allow or deny access (Default: allow)
- Actions: The list of allowed actions
Deny rules always override Allow rules.
Example
permission.yaml---
# yaml-language-server: $schema=../../config/schemas/permission.schema.json
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: deny-user-foo-playbook-run
spec:
description: deny user foo from running
subject:
person: foo@bar.com
actions:
- playbook:*
deny: true
object:
playbooks:
- name: "*" # this is a wildcard selector that matches any playbook
Schema
| Field | Description | Scheme |
|---|---|---|
actions* | List of allowed actions |
|
deny | Specifies if this is a deny rule. (Default: false) |
|
description | Description of the permission |
|
object.components | List of component resource selectors | |
object.configs | List of config resource selectors | |
object.connections | List of connection resource selectors | |
object.mcp | Grant the global MCP object permission. Do not combine |
|
object.playbooks | List of playbook resource selectors | |
object.scopes | List of Scopes to expand into selectors, by | []ScopeRef |
object.views | List of view references, by | []ViewRef |
subject.canary |
|
|
subject.group | Name of a permission group |
|
subject.notification |
|
|
subject.person | Email or ID of the person |
|
subject.playbook |
|
|
subject.plugin |
|
|
subject.scraper |
|
|
subject.team | Name or ID of the team |
|
subject.topology |
|
|
Deprecated fields
Mission Control ignores these fields. Use a Scope with object.scopes instead.
| Field | Description | Scheme |
|---|---|---|
agents | Mission Control ignores this field. List of agent names to restrict this permission to |
|
tags | Mission Control ignores this field. Key-value pairs of tags to restrict this permission to |
|
Objects
Objects define the resources the permission targets. You can define Objects using Resource Selectors.
| Object Type | Description |
|---|---|
playbooks | Automation playbooks in the system |
configs | Configuration items in the catalog |
connections | Connection configurations for external systems |
components | Topology components |
views | Views (dashboards) |
scopes | Scopes, which expand into the selectors they define |
mcp | The global MCP object. Do not combine mcp with any of the object types above |
A permission can target multiple object types. If you define multiple objects, Mission Control grants the permission only if the request matches all defined objects (AND condition).
Object Examples
Target All Playbooks
object:
playbooks:
- name: "*"
Target Playbooks in a Namespace
object:
playbooks:
- namespace: production
Target Configs with Labels
object:
configs:
- labels:
environment: production
Target Specific Connection
object:
connections:
- name: aws-production
Multiple Object Types (AND condition)
This permission allows running playbooks only on configs in the specified namespace:
---
# yaml-language-server: $schema=../../config/schemas/permission.schema.json
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: allow-check-notification-playbook-run
spec:
description: allow check notification to run playbook
subject:
notification: mc/check-alerts
actions:
- playbook:run
- playbook:approve
object:
playbooks:
- name: echo-config
Examples
Allow Team to Run All Playbooks
team-playbook-permission.yamlapiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: sre-run-playbooks
spec:
description: Allow SRE team to run any playbook
subject:
team: sre-team
actions:
- playbook:run
object:
playbooks:
- name: "*"
Deny User from Deleting Configs
deny-delete-permission.yamlapiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: deny-john-delete
spec:
description: Deny John from deleting any configs
deny: true
subject:
person: john@example.com
actions:
- delete
object:
configs:
- name: "*"
Allow Notification to Use Connection
notification-connection-permission.yamlapiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: alerts-slack-access
spec:
description: Allow alerts notification to use Slack connection
subject:
notification: monitoring/critical-alerts
actions:
- read
object:
connections:
- name: slack-alerts
Allow Playbook to Access AWS
playbook-aws-permission.yamlapiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: cleanup-aws-access
spec:
description: Allow cleanup playbook to use AWS connection
subject:
playbook: automation/cleanup-resources
actions:
- read
object:
connections:
- name: aws-production
Restrict by Agent (Multi-Tenancy)
Define a Scope that selects the agent's resources:
prod-agent-configs.yaml---
apiVersion: mission-control.flanksource.com/v1
kind: Scope
metadata:
name: prod-agent-configs
namespace: mc
spec:
description: Configs from production agents
targets:
- config:
agent: agent-prod-1
- config:
agent: agent-prod-2
This scope:
- Uses
targets[].config.agentto select config items from each production agent. - Combines both targets with OR logic, so a config from either agent matches.
Then reference the scope from a permission:
user-read-scope.yamlapiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: allow-guest-homelab-monitoring
namespace: mc
spec:
description: allow this user to run loki-logs playbook on any config
subject:
person: aditya+guest@flanksource.com
actions:
- read
object:
scopes:
- namespace: mc
name: homelab-monitoring
Restrict by Tags (Multi-Tenancy)
Define a Scope that selects resources by tag:
homelab-all-resources.yaml---
apiVersion: mission-control.flanksource.com/v1
kind: Scope
metadata:
name: homelab-monitoring
namespace: mc
spec:
description: All resources in homelab cluster monitoring namespace
targets:
- config:
tagSelector: "cluster=homelab,namespace=monitoring"
This scope:
- Uses
targets[].config.tagSelectorto match config items by their tags. - Accepts Kubernetes selector syntax, so it matches both the cluster and the namespace tag.
Reference it from a permission the same way as the agent example above.