Deny actions in custom roles
Currently, the custom role definition supports only whitelisted role actions. With the number of those constantly increasing (which is great by the way, kudos to the team!) it’s getting hard to track new ones and evaluate/adjust existing role definitions.
In this regard, would be great to have an ability to deny certain actions from the superset of allowed ones. For example, I want to give internal users ability to manage all aspects of the space, except for worker pool. Currently, the only way in this example is to maintain the custom role with curated list of actions without WORKER_POOL_ ones.
- Workaround
- No
Log in to comment and vote
Comments1
Black Breeze
Feb 19
Thanks for raising this Dmytro. I can see your reasoning here, and your request is consistent with how other permission systems (like AWS IAM) work. That said, we need to pick our battles carefully as a startup so I’m opening this to the popular voting to gauge demand.