mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add service_accounts workspace sharing mode (#23093)
Introduce a three-way workspace sharing setting (none, everyone, service_accounts) replacing the boolean workspace_sharing_disabled. In service_accounts mode, only service account-owned workspaces can be shared while regular members' share permissions are removed. Adds a new organization-service-account system role with per-org permissions reconciled alongside the existing organization-member system role. Related to: https://linear.app/codercom/issue/PLAT-28/feat-service-accounts-sharing-mode-and-rbac-role --------- Co-authored-by: Steven Masley <Emyrk@users.noreply.github.com> Co-authored-by: Kayla はな <mckayla@hey.com>
This commit is contained in:
co-authored by
Steven Masley
Kayla はな
parent
6b76e30321
commit
91ec0f1484
Generated
+31
-2
@@ -4262,7 +4262,7 @@
|
||||
"in": "body",
|
||||
"required": true,
|
||||
"schema": {
|
||||
"$ref": "#/definitions/codersdk.WorkspaceSharingSettings"
|
||||
"$ref": "#/definitions/codersdk.UpdateWorkspaceSharingSettingsRequest"
|
||||
}
|
||||
}
|
||||
],
|
||||
@@ -4270,7 +4270,7 @@
|
||||
"200": {
|
||||
"description": "OK",
|
||||
"schema": {
|
||||
"$ref": "#/definitions/codersdk.UpdateWorkspaceSharingSettingsRequest"
|
||||
"$ref": "#/definitions/codersdk.WorkspaceSharingSettings"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -17109,6 +17109,15 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"codersdk.ShareableWorkspaceOwners": {
|
||||
"type": "string",
|
||||
"enum": ["none", "everyone", "service_accounts"],
|
||||
"x-enum-varnames": [
|
||||
"ShareableWorkspaceOwnersNone",
|
||||
"ShareableWorkspaceOwnersEveryone",
|
||||
"ShareableWorkspaceOwnersServiceAccounts"
|
||||
]
|
||||
},
|
||||
"codersdk.SharedWorkspaceActor": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
@@ -18645,7 +18654,17 @@
|
||||
"codersdk.UpdateWorkspaceSharingSettingsRequest": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"shareable_workspace_owners": {
|
||||
"description": "ShareableWorkspaceOwners controls whose workspaces can be shared\nwithin the organization.",
|
||||
"enum": ["none", "everyone", "service_accounts"],
|
||||
"allOf": [
|
||||
{
|
||||
"$ref": "#/definitions/codersdk.ShareableWorkspaceOwners"
|
||||
}
|
||||
]
|
||||
},
|
||||
"sharing_disabled": {
|
||||
"description": "SharingDisabled is deprecated and left for backward compatibility\npurposes.\nDeprecated: use `ShareableWorkspaceOwners` instead",
|
||||
"type": "boolean"
|
||||
}
|
||||
}
|
||||
@@ -20384,7 +20403,17 @@
|
||||
"codersdk.WorkspaceSharingSettings": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"shareable_workspace_owners": {
|
||||
"description": "ShareableWorkspaceOwners controls whose workspaces can be shared\nwithin the organization.",
|
||||
"enum": ["none", "everyone", "service_accounts"],
|
||||
"allOf": [
|
||||
{
|
||||
"$ref": "#/definitions/codersdk.ShareableWorkspaceOwners"
|
||||
}
|
||||
]
|
||||
},
|
||||
"sharing_disabled": {
|
||||
"description": "SharingDisabled is deprecated and left for backward compatibility\npurposes.\nDeprecated: use `ShareableWorkspaceOwners` instead",
|
||||
"type": "boolean"
|
||||
},
|
||||
"sharing_globally_disabled": {
|
||||
|
||||
Reference in New Issue
Block a user