mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
docs: restructure docs (#14421)
Closes #13434 Supersedes #14182 --------- Co-authored-by: Ethan <39577870+ethanndickson@users.noreply.github.com> Co-authored-by: Ethan Dickson <ethan@coder.com> Co-authored-by: Ben Potter <ben@coder.com> Co-authored-by: Stephen Kirby <58410745+stirby@users.noreply.github.com> Co-authored-by: Stephen Kirby <me@skirby.dev> Co-authored-by: EdwardAngert <17991901+EdwardAngert@users.noreply.github.com> Co-authored-by: Edward Angert <EdwardAngert@users.noreply.github.com>
This commit is contained in:
co-authored by
Ethan
Ethan Dickson
Ben Potter
Stephen Kirby
Stephen Kirby
EdwardAngert
Edward Angert
parent
288df75686
commit
419eba5fb6
@@ -0,0 +1,44 @@
|
||||
# Groups and Roles
|
||||
|
||||
Groups and roles can be manually assigned in Coder. For production deployments,
|
||||
these can also be [managed and synced by the identity provider](./idp-sync.md).
|
||||
|
||||
## Groups
|
||||
|
||||
Groups are logical segmentations of users in Coder and can be used to control
|
||||
which templates developers can use. For example:
|
||||
|
||||
- Users within the `devops` group can access the `AWS-VM` template
|
||||
- Users within the `data-science` group can access the `Jupyter-Kubernetes`
|
||||
template
|
||||
|
||||
## Roles
|
||||
|
||||
Roles determine which actions users can take within the platform.
|
||||
|
||||
| | Auditor | User Admin | Template Admin | Owner |
|
||||
| --------------------------------------------------------------- | ------- | ---------- | -------------- | ----- |
|
||||
| Add and remove Users | | ✅ | | ✅ |
|
||||
| Manage groups (enterprise) (premium) | | ✅ | | ✅ |
|
||||
| Change User roles | | | | ✅ |
|
||||
| Manage **ALL** Templates | | | ✅ | ✅ |
|
||||
| View **ALL** Workspaces | | | ✅ | ✅ |
|
||||
| Update and delete **ALL** Workspaces | | | | ✅ |
|
||||
| Run [external provisioners](../provisioners.md) | | | ✅ | ✅ |
|
||||
| Execute and use **ALL** Workspaces | | | | ✅ |
|
||||
| View all user operation [Audit Logs](../security/audit-logs.md) | ✅ | | | ✅ |
|
||||
|
||||
A user may have one or more roles. All users have an implicit Member role that
|
||||
may use personal workspaces.
|
||||
|
||||
### Security notes
|
||||
|
||||
A malicious Template Admin could write a template that executes commands on the
|
||||
host (or `coder server` container), which potentially escalates their privileges
|
||||
or shuts down the Coder server. To avoid this, run
|
||||
[external provisioners](../provisioners.md).
|
||||
|
||||
In low-trust environments, we do not recommend giving users direct access to
|
||||
edit templates. Instead, use
|
||||
[CI/CD pipelines to update templates](../templates/managing-templates/change-management.md)
|
||||
with proper security scans and code reviews in place.
|
||||
Reference in New Issue
Block a user