mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
# Summary Implements https://linear.app/codercom/issue/AIGOV-282/add-ai-model-price-table-and-seed-generator This PR lays the groundwork for AI Bridge cost controls (per the AI Governance RFC). It adds the foundation needed for future cost tracking: a place to store per-model token prices, a way to keep those prices in sync with upstream pricing data, and a startup mechanism that ensures every deployment has prices loaded before AI Bridge starts processing requests. The price data comes from [models.dev](https://models.dev/), a community-maintained catalogue of AI provider pricing. A generator script fetches the latest prices, filters to Anthropic and OpenAI for now, and produces a seed file checked into the repository. On every server startup the seed is applied to the database, so new releases automatically pick up any price corrections that landed since the previous one. Existing rows are overwritten with the latest prices; rows for models no longer in the seed are left untouched. # Batching the AI model price seed: three approaches Context: at server startup we seed the `ai_model_prices` table from an embedded JSON price book (~70 rows today, will grow as we add providers, potentially 4000+). Each row is: ```text (provider, model, input_price, output_price, cache_read_price, cache_write_price) ``` Any of the four price columns can be: - `NULL` → “price unknown for this dimension” - explicit `0` → “free” The batch must be an UPSERT so re-running is idempotent and existing rows pick up new prices. We considered three implementations. --- ## Approach 1 — Per-row UPSERT in a Go loop ```go for _, row := range rows { if err := db.UpsertAIModelPrice(ctx, database.UpsertAIModelPriceParams{ Provider: row.Provider, Model: row.Model, InputPrice: nullInt64(row.InputPrice), // ... }); err != nil { return err } } ``` ### Pros - Trivial. - NULL handling falls out naturally from `sql.NullInt64`. ### Cons - `N` round-trips per seed. - With ~70 rows that means ~70 statement executions on every startup, even inside a transaction. - Doesn't scale gracefully as the price book grows, potentially 4000+. --- ## Approach 2 — `UNNEST` with parallel arrays Pass each column as a separate Go slice. Postgres unnests them in parallel into a virtual table, then `INSERT ... SELECT`. ```sql INSERT INTO ai_model_prices ( provider, model, input_price, output_price, cache_read_price, cache_write_price ) SELECT UNNEST(@providers::text[]), UNNEST(@models::text[]), NULLIF(UNNEST(@input_prices::bigint[]), -1), NULLIF(UNNEST(@output_prices::bigint[]), -1), NULLIF(UNNEST(@cache_read_prices::bigint[]), -1), NULLIF(UNNEST(@cache_write_prices::bigint[]), -1) ON CONFLICT (provider, model) DO UPDATE SET input_price = EXCLUDED.input_price, output_price = EXCLUDED.output_price, cache_read_price = EXCLUDED.cache_read_price, cache_write_price = EXCLUDED.cache_write_price, updated_at = NOW(); ``` Go side: flatten rows into six parallel slices. Use a sentinel (`-1`) for “missing”, since `lib/pq` can't encode `NULL` into a `bigint[]` element. ```go providers := make([]string, len(rows)) models := make([]string, len(rows)) inputs := make([]int64, len(rows)) outputs := make([]int64, len(rows)) cacheR := make([]int64, len(rows)) cacheW := make([]int64, len(rows)) for i, r := range rows { providers[i] = r.Provider models[i] = r.Model inputs[i] = -1 if r.InputPrice != nil { inputs[i] = *r.InputPrice } outputs[i] = -1 if r.OutputPrice != nil { outputs[i] = *r.OutputPrice } cacheR[i] = -1 if r.CacheReadPrice != nil { cacheR[i] = *r.CacheReadPrice } cacheW[i] = -1 if r.CacheWritePrice != nil { cacheW[i] = *r.CacheWritePrice } } return db.UpsertAIModelPrices(ctx, database.UpsertAIModelPricesParams{ Providers: providers, Models: models, InputPrices: inputs, OutputPrices: outputs, CacheReadPrices: cacheR, CacheWritePrices: cacheW, }) ``` ### Pros - Single round-trip. ### Cons - The generated `sqlc` params become plain `[]int64`, which can't represent `NULL`. --- ## Approach 3 — `jsonb_array_elements` over a single `@seed::jsonb` (chosen) Pass the raw seed JSON as one parameter; let Postgres expand and parse it. ```sql INSERT INTO ai_model_prices ( provider, model, input_price, output_price, cache_read_price, cache_write_price ) SELECT elem->>'provider', elem->>'model', (elem->>'input_price')::bigint, (elem->>'output_price')::bigint, (elem->>'cache_read_price')::bigint, (elem->>'cache_write_price')::bigint FROM jsonb_array_elements(@seed::jsonb) AS elem ON CONFLICT (provider, model) DO UPDATE SET input_price = EXCLUDED.input_price, output_price = EXCLUDED.output_price, cache_read_price = EXCLUDED.cache_read_price, cache_write_price = EXCLUDED.cache_write_price, updated_at = NOW(); ``` Go side reduces to: ```go return db.UpsertAIModelPrices(ctx, seedJSON) ``` ### Pros - Single round-trip. - NULLs fall out naturally: - `(elem->>'cache_write_price')::bigint` becomes `NULL` - no sentinels - The seed is already JSON: - Existing precedent: - `jsonb_array_elements` is already used elsewhere in the codebase ### Cons - Less type-safe at the SQL boundary than `UNNEST` - Slightly less standard than `UNNEST` - Readers need familiarity with: - `jsonb_array_elements` - `->>` extraction syntax - Postgres pays JSON parse cost - negligible at our scale --- --- # Decision We picked Approach 3. It collapses the round-trips like `UNNEST` does, but without: - nullable-array workarounds - sentinel values
274 lines
19 KiB
Go
274 lines
19 KiB
Go
// Code generated by scripts/apikeyscopesgen. DO NOT EDIT.
|
|
package codersdk
|
|
|
|
const (
|
|
// Deprecated: use codersdk.APIKeyScopeCoderAll instead.
|
|
APIKeyScopeAll APIKeyScope = "all"
|
|
// Deprecated: use codersdk.APIKeyScopeCoderApplicationConnect instead.
|
|
APIKeyScopeApplicationConnect APIKeyScope = "application_connect"
|
|
APIKeyScopeAiModelPriceAll APIKeyScope = "ai_model_price:*"
|
|
APIKeyScopeAiModelPriceRead APIKeyScope = "ai_model_price:read"
|
|
APIKeyScopeAiModelPriceUpdate APIKeyScope = "ai_model_price:update"
|
|
APIKeyScopeAiSeatAll APIKeyScope = "ai_seat:*"
|
|
APIKeyScopeAiSeatCreate APIKeyScope = "ai_seat:create"
|
|
APIKeyScopeAiSeatRead APIKeyScope = "ai_seat:read"
|
|
APIKeyScopeAibridgeInterceptionAll APIKeyScope = "aibridge_interception:*"
|
|
APIKeyScopeAibridgeInterceptionCreate APIKeyScope = "aibridge_interception:create"
|
|
APIKeyScopeAibridgeInterceptionRead APIKeyScope = "aibridge_interception:read"
|
|
APIKeyScopeAibridgeInterceptionUpdate APIKeyScope = "aibridge_interception:update"
|
|
APIKeyScopeApiKeyAll APIKeyScope = "api_key:*"
|
|
APIKeyScopeApiKeyCreate APIKeyScope = "api_key:create"
|
|
APIKeyScopeApiKeyDelete APIKeyScope = "api_key:delete"
|
|
APIKeyScopeApiKeyRead APIKeyScope = "api_key:read"
|
|
APIKeyScopeApiKeyUpdate APIKeyScope = "api_key:update"
|
|
APIKeyScopeAssignOrgRoleAll APIKeyScope = "assign_org_role:*"
|
|
APIKeyScopeAssignOrgRoleAssign APIKeyScope = "assign_org_role:assign"
|
|
APIKeyScopeAssignOrgRoleCreate APIKeyScope = "assign_org_role:create"
|
|
APIKeyScopeAssignOrgRoleDelete APIKeyScope = "assign_org_role:delete"
|
|
APIKeyScopeAssignOrgRoleRead APIKeyScope = "assign_org_role:read"
|
|
APIKeyScopeAssignOrgRoleUnassign APIKeyScope = "assign_org_role:unassign"
|
|
APIKeyScopeAssignOrgRoleUpdate APIKeyScope = "assign_org_role:update"
|
|
APIKeyScopeAssignRoleAll APIKeyScope = "assign_role:*"
|
|
APIKeyScopeAssignRoleAssign APIKeyScope = "assign_role:assign"
|
|
APIKeyScopeAssignRoleRead APIKeyScope = "assign_role:read"
|
|
APIKeyScopeAssignRoleUnassign APIKeyScope = "assign_role:unassign"
|
|
APIKeyScopeAuditLogAll APIKeyScope = "audit_log:*"
|
|
APIKeyScopeAuditLogCreate APIKeyScope = "audit_log:create"
|
|
APIKeyScopeAuditLogRead APIKeyScope = "audit_log:read"
|
|
APIKeyScopeBoundaryUsageAll APIKeyScope = "boundary_usage:*"
|
|
APIKeyScopeBoundaryUsageDelete APIKeyScope = "boundary_usage:delete"
|
|
APIKeyScopeBoundaryUsageRead APIKeyScope = "boundary_usage:read"
|
|
APIKeyScopeBoundaryUsageUpdate APIKeyScope = "boundary_usage:update"
|
|
APIKeyScopeChatAll APIKeyScope = "chat:*"
|
|
APIKeyScopeChatCreate APIKeyScope = "chat:create"
|
|
APIKeyScopeChatDelete APIKeyScope = "chat:delete"
|
|
APIKeyScopeChatRead APIKeyScope = "chat:read"
|
|
APIKeyScopeChatUpdate APIKeyScope = "chat:update"
|
|
APIKeyScopeCoderAll APIKeyScope = "coder:all"
|
|
APIKeyScopeCoderApikeysManageSelf APIKeyScope = "coder:apikeys.manage_self"
|
|
APIKeyScopeCoderApplicationConnect APIKeyScope = "coder:application_connect"
|
|
APIKeyScopeCoderTemplatesAuthor APIKeyScope = "coder:templates.author"
|
|
APIKeyScopeCoderTemplatesBuild APIKeyScope = "coder:templates.build"
|
|
APIKeyScopeCoderWorkspacesAccess APIKeyScope = "coder:workspaces.access"
|
|
APIKeyScopeCoderWorkspacesCreate APIKeyScope = "coder:workspaces.create"
|
|
APIKeyScopeCoderWorkspacesDelete APIKeyScope = "coder:workspaces.delete"
|
|
APIKeyScopeCoderWorkspacesOperate APIKeyScope = "coder:workspaces.operate"
|
|
APIKeyScopeConnectionLogAll APIKeyScope = "connection_log:*"
|
|
APIKeyScopeConnectionLogRead APIKeyScope = "connection_log:read"
|
|
APIKeyScopeConnectionLogUpdate APIKeyScope = "connection_log:update"
|
|
APIKeyScopeCryptoKeyAll APIKeyScope = "crypto_key:*"
|
|
APIKeyScopeCryptoKeyCreate APIKeyScope = "crypto_key:create"
|
|
APIKeyScopeCryptoKeyDelete APIKeyScope = "crypto_key:delete"
|
|
APIKeyScopeCryptoKeyRead APIKeyScope = "crypto_key:read"
|
|
APIKeyScopeCryptoKeyUpdate APIKeyScope = "crypto_key:update"
|
|
APIKeyScopeDebugInfoAll APIKeyScope = "debug_info:*"
|
|
APIKeyScopeDebugInfoRead APIKeyScope = "debug_info:read"
|
|
APIKeyScopeDeploymentConfigAll APIKeyScope = "deployment_config:*"
|
|
APIKeyScopeDeploymentConfigRead APIKeyScope = "deployment_config:read"
|
|
APIKeyScopeDeploymentConfigUpdate APIKeyScope = "deployment_config:update"
|
|
APIKeyScopeDeploymentStatsAll APIKeyScope = "deployment_stats:*"
|
|
APIKeyScopeDeploymentStatsRead APIKeyScope = "deployment_stats:read"
|
|
APIKeyScopeFileAll APIKeyScope = "file:*"
|
|
APIKeyScopeFileCreate APIKeyScope = "file:create"
|
|
APIKeyScopeFileRead APIKeyScope = "file:read"
|
|
APIKeyScopeGroupAll APIKeyScope = "group:*"
|
|
APIKeyScopeGroupCreate APIKeyScope = "group:create"
|
|
APIKeyScopeGroupDelete APIKeyScope = "group:delete"
|
|
APIKeyScopeGroupRead APIKeyScope = "group:read"
|
|
APIKeyScopeGroupUpdate APIKeyScope = "group:update"
|
|
APIKeyScopeGroupMemberAll APIKeyScope = "group_member:*"
|
|
APIKeyScopeGroupMemberRead APIKeyScope = "group_member:read"
|
|
APIKeyScopeIdpsyncSettingsAll APIKeyScope = "idpsync_settings:*"
|
|
APIKeyScopeIdpsyncSettingsRead APIKeyScope = "idpsync_settings:read"
|
|
APIKeyScopeIdpsyncSettingsUpdate APIKeyScope = "idpsync_settings:update"
|
|
APIKeyScopeInboxNotificationAll APIKeyScope = "inbox_notification:*"
|
|
APIKeyScopeInboxNotificationCreate APIKeyScope = "inbox_notification:create"
|
|
APIKeyScopeInboxNotificationRead APIKeyScope = "inbox_notification:read"
|
|
APIKeyScopeInboxNotificationUpdate APIKeyScope = "inbox_notification:update"
|
|
APIKeyScopeLicenseAll APIKeyScope = "license:*"
|
|
APIKeyScopeLicenseCreate APIKeyScope = "license:create"
|
|
APIKeyScopeLicenseDelete APIKeyScope = "license:delete"
|
|
APIKeyScopeLicenseRead APIKeyScope = "license:read"
|
|
APIKeyScopeNotificationMessageAll APIKeyScope = "notification_message:*"
|
|
APIKeyScopeNotificationMessageCreate APIKeyScope = "notification_message:create"
|
|
APIKeyScopeNotificationMessageDelete APIKeyScope = "notification_message:delete"
|
|
APIKeyScopeNotificationMessageRead APIKeyScope = "notification_message:read"
|
|
APIKeyScopeNotificationMessageUpdate APIKeyScope = "notification_message:update"
|
|
APIKeyScopeNotificationPreferenceAll APIKeyScope = "notification_preference:*"
|
|
APIKeyScopeNotificationPreferenceRead APIKeyScope = "notification_preference:read"
|
|
APIKeyScopeNotificationPreferenceUpdate APIKeyScope = "notification_preference:update"
|
|
APIKeyScopeNotificationTemplateAll APIKeyScope = "notification_template:*"
|
|
APIKeyScopeNotificationTemplateRead APIKeyScope = "notification_template:read"
|
|
APIKeyScopeNotificationTemplateUpdate APIKeyScope = "notification_template:update"
|
|
APIKeyScopeOauth2AppAll APIKeyScope = "oauth2_app:*"
|
|
APIKeyScopeOauth2AppCreate APIKeyScope = "oauth2_app:create"
|
|
APIKeyScopeOauth2AppDelete APIKeyScope = "oauth2_app:delete"
|
|
APIKeyScopeOauth2AppRead APIKeyScope = "oauth2_app:read"
|
|
APIKeyScopeOauth2AppUpdate APIKeyScope = "oauth2_app:update"
|
|
APIKeyScopeOauth2AppCodeTokenAll APIKeyScope = "oauth2_app_code_token:*"
|
|
APIKeyScopeOauth2AppCodeTokenCreate APIKeyScope = "oauth2_app_code_token:create"
|
|
APIKeyScopeOauth2AppCodeTokenDelete APIKeyScope = "oauth2_app_code_token:delete"
|
|
APIKeyScopeOauth2AppCodeTokenRead APIKeyScope = "oauth2_app_code_token:read"
|
|
APIKeyScopeOauth2AppSecretAll APIKeyScope = "oauth2_app_secret:*"
|
|
APIKeyScopeOauth2AppSecretCreate APIKeyScope = "oauth2_app_secret:create"
|
|
APIKeyScopeOauth2AppSecretDelete APIKeyScope = "oauth2_app_secret:delete"
|
|
APIKeyScopeOauth2AppSecretRead APIKeyScope = "oauth2_app_secret:read"
|
|
APIKeyScopeOauth2AppSecretUpdate APIKeyScope = "oauth2_app_secret:update"
|
|
APIKeyScopeOrganizationAll APIKeyScope = "organization:*"
|
|
APIKeyScopeOrganizationCreate APIKeyScope = "organization:create"
|
|
APIKeyScopeOrganizationDelete APIKeyScope = "organization:delete"
|
|
APIKeyScopeOrganizationRead APIKeyScope = "organization:read"
|
|
APIKeyScopeOrganizationUpdate APIKeyScope = "organization:update"
|
|
APIKeyScopeOrganizationMemberAll APIKeyScope = "organization_member:*"
|
|
APIKeyScopeOrganizationMemberCreate APIKeyScope = "organization_member:create"
|
|
APIKeyScopeOrganizationMemberDelete APIKeyScope = "organization_member:delete"
|
|
APIKeyScopeOrganizationMemberRead APIKeyScope = "organization_member:read"
|
|
APIKeyScopeOrganizationMemberUpdate APIKeyScope = "organization_member:update"
|
|
APIKeyScopePrebuiltWorkspaceAll APIKeyScope = "prebuilt_workspace:*"
|
|
APIKeyScopePrebuiltWorkspaceDelete APIKeyScope = "prebuilt_workspace:delete"
|
|
APIKeyScopePrebuiltWorkspaceUpdate APIKeyScope = "prebuilt_workspace:update"
|
|
APIKeyScopeProvisionerDaemonAll APIKeyScope = "provisioner_daemon:*"
|
|
APIKeyScopeProvisionerDaemonCreate APIKeyScope = "provisioner_daemon:create"
|
|
APIKeyScopeProvisionerDaemonDelete APIKeyScope = "provisioner_daemon:delete"
|
|
APIKeyScopeProvisionerDaemonRead APIKeyScope = "provisioner_daemon:read"
|
|
APIKeyScopeProvisionerDaemonUpdate APIKeyScope = "provisioner_daemon:update"
|
|
APIKeyScopeProvisionerJobsAll APIKeyScope = "provisioner_jobs:*"
|
|
APIKeyScopeProvisionerJobsCreate APIKeyScope = "provisioner_jobs:create"
|
|
APIKeyScopeProvisionerJobsRead APIKeyScope = "provisioner_jobs:read"
|
|
APIKeyScopeProvisionerJobsUpdate APIKeyScope = "provisioner_jobs:update"
|
|
APIKeyScopeReplicasAll APIKeyScope = "replicas:*"
|
|
APIKeyScopeReplicasRead APIKeyScope = "replicas:read"
|
|
APIKeyScopeSystemAll APIKeyScope = "system:*"
|
|
APIKeyScopeSystemCreate APIKeyScope = "system:create"
|
|
APIKeyScopeSystemDelete APIKeyScope = "system:delete"
|
|
APIKeyScopeSystemRead APIKeyScope = "system:read"
|
|
APIKeyScopeSystemUpdate APIKeyScope = "system:update"
|
|
APIKeyScopeTailnetCoordinatorAll APIKeyScope = "tailnet_coordinator:*"
|
|
APIKeyScopeTailnetCoordinatorCreate APIKeyScope = "tailnet_coordinator:create"
|
|
APIKeyScopeTailnetCoordinatorDelete APIKeyScope = "tailnet_coordinator:delete"
|
|
APIKeyScopeTailnetCoordinatorRead APIKeyScope = "tailnet_coordinator:read"
|
|
APIKeyScopeTailnetCoordinatorUpdate APIKeyScope = "tailnet_coordinator:update"
|
|
APIKeyScopeTaskAll APIKeyScope = "task:*"
|
|
APIKeyScopeTaskCreate APIKeyScope = "task:create"
|
|
APIKeyScopeTaskDelete APIKeyScope = "task:delete"
|
|
APIKeyScopeTaskRead APIKeyScope = "task:read"
|
|
APIKeyScopeTaskUpdate APIKeyScope = "task:update"
|
|
APIKeyScopeTemplateAll APIKeyScope = "template:*"
|
|
APIKeyScopeTemplateCreate APIKeyScope = "template:create"
|
|
APIKeyScopeTemplateDelete APIKeyScope = "template:delete"
|
|
APIKeyScopeTemplateRead APIKeyScope = "template:read"
|
|
APIKeyScopeTemplateUpdate APIKeyScope = "template:update"
|
|
APIKeyScopeTemplateUse APIKeyScope = "template:use"
|
|
APIKeyScopeTemplateViewInsights APIKeyScope = "template:view_insights"
|
|
APIKeyScopeUsageEventAll APIKeyScope = "usage_event:*"
|
|
APIKeyScopeUsageEventCreate APIKeyScope = "usage_event:create"
|
|
APIKeyScopeUsageEventRead APIKeyScope = "usage_event:read"
|
|
APIKeyScopeUsageEventUpdate APIKeyScope = "usage_event:update"
|
|
APIKeyScopeUserAll APIKeyScope = "user:*"
|
|
APIKeyScopeUserCreate APIKeyScope = "user:create"
|
|
APIKeyScopeUserDelete APIKeyScope = "user:delete"
|
|
APIKeyScopeUserRead APIKeyScope = "user:read"
|
|
APIKeyScopeUserReadPersonal APIKeyScope = "user:read_personal"
|
|
APIKeyScopeUserUpdate APIKeyScope = "user:update"
|
|
APIKeyScopeUserUpdatePersonal APIKeyScope = "user:update_personal"
|
|
APIKeyScopeUserSecretAll APIKeyScope = "user_secret:*"
|
|
APIKeyScopeUserSecretCreate APIKeyScope = "user_secret:create"
|
|
APIKeyScopeUserSecretDelete APIKeyScope = "user_secret:delete"
|
|
APIKeyScopeUserSecretRead APIKeyScope = "user_secret:read"
|
|
APIKeyScopeUserSecretUpdate APIKeyScope = "user_secret:update"
|
|
APIKeyScopeWebpushSubscriptionAll APIKeyScope = "webpush_subscription:*"
|
|
APIKeyScopeWebpushSubscriptionCreate APIKeyScope = "webpush_subscription:create"
|
|
APIKeyScopeWebpushSubscriptionDelete APIKeyScope = "webpush_subscription:delete"
|
|
APIKeyScopeWebpushSubscriptionRead APIKeyScope = "webpush_subscription:read"
|
|
APIKeyScopeWorkspaceAll APIKeyScope = "workspace:*"
|
|
APIKeyScopeWorkspaceApplicationConnect APIKeyScope = "workspace:application_connect"
|
|
APIKeyScopeWorkspaceCreate APIKeyScope = "workspace:create"
|
|
APIKeyScopeWorkspaceCreateAgent APIKeyScope = "workspace:create_agent"
|
|
APIKeyScopeWorkspaceDelete APIKeyScope = "workspace:delete"
|
|
APIKeyScopeWorkspaceDeleteAgent APIKeyScope = "workspace:delete_agent"
|
|
APIKeyScopeWorkspaceRead APIKeyScope = "workspace:read"
|
|
APIKeyScopeWorkspaceShare APIKeyScope = "workspace:share"
|
|
APIKeyScopeWorkspaceSsh APIKeyScope = "workspace:ssh"
|
|
APIKeyScopeWorkspaceStart APIKeyScope = "workspace:start"
|
|
APIKeyScopeWorkspaceStop APIKeyScope = "workspace:stop"
|
|
APIKeyScopeWorkspaceUpdate APIKeyScope = "workspace:update"
|
|
APIKeyScopeWorkspaceUpdateAgent APIKeyScope = "workspace:update_agent"
|
|
APIKeyScopeWorkspaceAgentDevcontainersAll APIKeyScope = "workspace_agent_devcontainers:*"
|
|
APIKeyScopeWorkspaceAgentDevcontainersCreate APIKeyScope = "workspace_agent_devcontainers:create"
|
|
APIKeyScopeWorkspaceAgentResourceMonitorAll APIKeyScope = "workspace_agent_resource_monitor:*"
|
|
APIKeyScopeWorkspaceAgentResourceMonitorCreate APIKeyScope = "workspace_agent_resource_monitor:create"
|
|
APIKeyScopeWorkspaceAgentResourceMonitorRead APIKeyScope = "workspace_agent_resource_monitor:read"
|
|
APIKeyScopeWorkspaceAgentResourceMonitorUpdate APIKeyScope = "workspace_agent_resource_monitor:update"
|
|
APIKeyScopeWorkspaceDormantAll APIKeyScope = "workspace_dormant:*"
|
|
APIKeyScopeWorkspaceDormantApplicationConnect APIKeyScope = "workspace_dormant:application_connect"
|
|
APIKeyScopeWorkspaceDormantCreate APIKeyScope = "workspace_dormant:create"
|
|
APIKeyScopeWorkspaceDormantCreateAgent APIKeyScope = "workspace_dormant:create_agent"
|
|
APIKeyScopeWorkspaceDormantDelete APIKeyScope = "workspace_dormant:delete"
|
|
APIKeyScopeWorkspaceDormantDeleteAgent APIKeyScope = "workspace_dormant:delete_agent"
|
|
APIKeyScopeWorkspaceDormantRead APIKeyScope = "workspace_dormant:read"
|
|
APIKeyScopeWorkspaceDormantShare APIKeyScope = "workspace_dormant:share"
|
|
APIKeyScopeWorkspaceDormantSsh APIKeyScope = "workspace_dormant:ssh"
|
|
APIKeyScopeWorkspaceDormantStart APIKeyScope = "workspace_dormant:start"
|
|
APIKeyScopeWorkspaceDormantStop APIKeyScope = "workspace_dormant:stop"
|
|
APIKeyScopeWorkspaceDormantUpdate APIKeyScope = "workspace_dormant:update"
|
|
APIKeyScopeWorkspaceDormantUpdateAgent APIKeyScope = "workspace_dormant:update_agent"
|
|
APIKeyScopeWorkspaceProxyAll APIKeyScope = "workspace_proxy:*"
|
|
APIKeyScopeWorkspaceProxyCreate APIKeyScope = "workspace_proxy:create"
|
|
APIKeyScopeWorkspaceProxyDelete APIKeyScope = "workspace_proxy:delete"
|
|
APIKeyScopeWorkspaceProxyRead APIKeyScope = "workspace_proxy:read"
|
|
APIKeyScopeWorkspaceProxyUpdate APIKeyScope = "workspace_proxy:update"
|
|
)
|
|
|
|
// PublicAPIKeyScopes lists all public low-level API key scopes.
|
|
var PublicAPIKeyScopes = []APIKeyScope{
|
|
APIKeyScopeApiKeyAll,
|
|
APIKeyScopeApiKeyCreate,
|
|
APIKeyScopeApiKeyDelete,
|
|
APIKeyScopeApiKeyRead,
|
|
APIKeyScopeApiKeyUpdate,
|
|
APIKeyScopeCoderAll,
|
|
APIKeyScopeCoderApikeysManageSelf,
|
|
APIKeyScopeCoderApplicationConnect,
|
|
APIKeyScopeCoderTemplatesAuthor,
|
|
APIKeyScopeCoderTemplatesBuild,
|
|
APIKeyScopeCoderWorkspacesAccess,
|
|
APIKeyScopeCoderWorkspacesCreate,
|
|
APIKeyScopeCoderWorkspacesDelete,
|
|
APIKeyScopeCoderWorkspacesOperate,
|
|
APIKeyScopeFileAll,
|
|
APIKeyScopeFileCreate,
|
|
APIKeyScopeFileRead,
|
|
APIKeyScopeOrganizationAll,
|
|
APIKeyScopeOrganizationDelete,
|
|
APIKeyScopeOrganizationRead,
|
|
APIKeyScopeOrganizationUpdate,
|
|
APIKeyScopeTaskAll,
|
|
APIKeyScopeTaskCreate,
|
|
APIKeyScopeTaskDelete,
|
|
APIKeyScopeTaskRead,
|
|
APIKeyScopeTaskUpdate,
|
|
APIKeyScopeTemplateAll,
|
|
APIKeyScopeTemplateCreate,
|
|
APIKeyScopeTemplateDelete,
|
|
APIKeyScopeTemplateRead,
|
|
APIKeyScopeTemplateUpdate,
|
|
APIKeyScopeTemplateUse,
|
|
APIKeyScopeUserRead,
|
|
APIKeyScopeUserReadPersonal,
|
|
APIKeyScopeUserUpdatePersonal,
|
|
APIKeyScopeUserSecretAll,
|
|
APIKeyScopeUserSecretCreate,
|
|
APIKeyScopeUserSecretDelete,
|
|
APIKeyScopeUserSecretRead,
|
|
APIKeyScopeUserSecretUpdate,
|
|
APIKeyScopeWorkspaceAll,
|
|
APIKeyScopeWorkspaceApplicationConnect,
|
|
APIKeyScopeWorkspaceCreate,
|
|
APIKeyScopeWorkspaceDelete,
|
|
APIKeyScopeWorkspaceRead,
|
|
APIKeyScopeWorkspaceSsh,
|
|
APIKeyScopeWorkspaceStart,
|
|
APIKeyScopeWorkspaceStop,
|
|
APIKeyScopeWorkspaceUpdate,
|
|
}
|