Skip to main content

Permission Actions Reference

Core Actions​

These are the fundamental CRUD operations that can be applied to any resource in Mission Control.

ActionDescription
*Grants full access to all operations on the specified resource. Use with caution as this provides unrestricted access.
create,read,update,deleteExplicit specification of all CRUD operations. Functionally equivalent to * but more explicit.
createAllows creating new instances of a resource
readAllows viewing and listing resources
updateAllows modifying existing resources
deleteAllows removing resources

Playbook-Specific Actions​

These actions are specific to playbook resources and provide fine-grained control over playbook execution and approval workflows.

ActionDescription
playbook:runAllows execution of playbooks
playbook:approveAllows approving playbook execution requests
playbook:cancelAllows canceling an in-flight playbook run

MCP Actions​

These actions control access to the MCP endpoint.

ActionDescription
mcp:useAllows connecting to and using the MCP endpoint
mcp:runAllows MCP-triggered playbook runs. Intended for playbook-scoped permissions

Plugin Actions​

Plugins contribute their own actions using two prefixes.

ActionDescription
invoke:<plugin>:<operation>Allows invoking an operation exposed by a plugin
plugin-role:<plugin>:<role>Grants a role that the plugin defines

Usage Examples​

Basic Configuration Access​

apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: dev-team-config-access
spec:
subject:
team: developers
object:
configs:
- namespace: dev
- namespace: staging
actions:
- "playbook:run"
- "playbook:approve"
- "create,read,update,delete"

Approval Workflow​

apiVersion: mission-control.flanksource.com/v1
kind: Permission
metadata:
name: lead-approval-permission
spec:
subject:
team: team-leads
object:
playbooks:
- tags:
environment: production
actions:
- "read"
- "playbook:approve"