Skip to main content

Permission

A Permission defines access control rules that grant or deny specific actions to subjects on target objects.

Overview​

A Permission has 4 parts:

  • Subject: The user or service requesting access
  • Object: The resources this permission affects (playbooks, connections, or configs)
  • Effect: Whether to allow or deny access (Default: allow)
  • Actions: The list of allowed actions
info

Deny rules always override Allow rules.

Example​

permission.yaml
---
# yaml-language-server: $schema=../../config/schemas/permission.schema.json
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: deny-user-foo-playbook-run
spec:
description: deny user foo from running
subject:
person: foo@bar.com
actions:
- playbook:*
deny: true
object:
playbooks:
- name: "*" # this is a wildcard selector that matches any playbook

Schema​

FieldDescriptionScheme
actions*

List of allowed actions

[]string

deny

Specifies if this is a deny rule. (Default: false)

boolean

description

Description of the permission

string

object.components

List of component resource selectors

ResourceSelector

object.configs

List of config resource selectors

ResourceSelector

object.connections

List of connection resource selectors

ResourceSelector

object.mcp

Grant the global MCP object permission. Do not combine object.mcp with any selector or scope

boolean

object.playbooks

List of playbook resource selectors

ResourceSelector

object.scopes

List of Scopes to expand into selectors, by id or namespace/name

[]ScopeRef

object.views

List of view references, by id or namespace/name

[]ViewRef

subject.canary

<namespace>/<name> of the canary

string

subject.group

Name of a permission group

string

subject.notification

<namespace>/<name> of the notification

string

subject.person

Email or ID of the person

string

subject.playbook

<namespace>/<name> of the playbook

string

subject.plugin

<namespace>/<name> or /<name> of the plugin

string

subject.scraper

<namespace>/<name> of the scraper

string

subject.team

Name or ID of the team

string

subject.topology

<namespace>/<name> of the topology

string

Deprecated fields​

Deprecated

Mission Control ignores these fields. Use a Scope with object.scopes instead.

FieldDescriptionScheme
agents

Mission Control ignores this field. List of agent names to restrict this permission to

[]string

tags

Mission Control ignores this field. Key-value pairs of tags to restrict this permission to

map[string]string

Objects​

Objects define the resources the permission targets. You can define Objects using Resource Selectors.

Object TypeDescription
playbooksAutomation playbooks in the system
configsConfiguration items in the catalog
connectionsConnection configurations for external systems
componentsTopology components
viewsViews (dashboards)
scopesScopes, which expand into the selectors they define
mcpThe global MCP object. Do not combine mcp with any of the object types above

A permission can target multiple object types. If you define multiple objects, Mission Control grants the permission only if the request matches all defined objects (AND condition).

Object Examples​

Target All Playbooks
object:
playbooks:
- name: "*"
Target Playbooks in a Namespace
object:
playbooks:
- namespace: production
Target Configs with Labels
object:
configs:
- labels:
environment: production
Target Specific Connection
object:
connections:
- name: aws-production
Multiple Object Types (AND condition)

This permission allows running playbooks only on configs in the specified namespace:

---
# yaml-language-server: $schema=../../config/schemas/permission.schema.json
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: allow-check-notification-playbook-run
spec:
description: allow check notification to run playbook
subject:
notification: mc/check-alerts
actions:
- playbook:run
- playbook:approve
object:
playbooks:
- name: echo-config

Examples​

Allow Team to Run All Playbooks
team-playbook-permission.yaml
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: sre-run-playbooks
spec:
description: Allow SRE team to run any playbook
subject:
team: sre-team
actions:
- playbook:run
object:
playbooks:
- name: "*"
Deny User from Deleting Configs
deny-delete-permission.yaml
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: deny-john-delete
spec:
description: Deny John from deleting any configs
deny: true
subject:
person: john@example.com
actions:
- delete
object:
configs:
- name: "*"
Allow Notification to Use Connection
notification-connection-permission.yaml
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: alerts-slack-access
spec:
description: Allow alerts notification to use Slack connection
subject:
notification: monitoring/critical-alerts
actions:
- read
object:
connections:
- name: slack-alerts
Allow Playbook to Access AWS
playbook-aws-permission.yaml
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: cleanup-aws-access
spec:
description: Allow cleanup playbook to use AWS connection
subject:
playbook: automation/cleanup-resources
actions:
- read
object:
connections:
- name: aws-production
Restrict by Agent (Multi-Tenancy)

Define a Scope that selects the agent's resources:

prod-agent-configs.yaml
---
apiVersion: mission-control.flanksource.com/v1
kind: Scope
metadata:
name: prod-agent-configs
namespace: mc
spec:
description: Configs from production agents
targets:
- config:
agent: agent-prod-1
- config:
agent: agent-prod-2

This scope:

  1. Uses targets[].config.agent to select config items from each production agent.
  2. Combines both targets with OR logic, so a config from either agent matches.

Then reference the scope from a permission:

user-read-scope.yaml
apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: allow-guest-homelab-monitoring
namespace: mc
spec:
description: allow this user to run loki-logs playbook on any config
subject:
person: aditya+guest@flanksource.com
actions:
- read
object:
scopes:
- namespace: mc
name: homelab-monitoring
Restrict by Tags (Multi-Tenancy)

Define a Scope that selects resources by tag:

homelab-all-resources.yaml
---
apiVersion: mission-control.flanksource.com/v1
kind: Scope
metadata:
name: homelab-monitoring
namespace: mc
spec:
description: All resources in homelab cluster monitoring namespace
targets:
- config:
tagSelector: "cluster=homelab,namespace=monitoring"

This scope:

  1. Uses targets[].config.tagSelector to match config items by their tags.
  2. Accepts Kubernetes selector syntax, so it matches both the cluster and the namespace tag.

Reference it from a permission the same way as the agent example above.