Policy Workbench & Simulation Panel: Granular View / Access Control
Enable granular, role-based access control for the Policy Workbench and Policy Simulation Panel, allowing non-account (non-root) administrators to:
View policy sampling results on a per-policy basis
Access sampled input data (where permitted)
Have read-only access to the Policy Simulation Panel
Doc referenced:
https://docs.spacelift.io/concepts/policy#is-policy-sampling-safe
Requested Enhancement
Introduce granular RBAC controls for policy-related tooling, such as:
Per-Policy Sampling Access
Ability to grant sampling visibility on a per-policy basis.
Scoped access tied to specific policies, stacks, or spaces (if applicable).
Read-Only Policy Simulation Access
Allow designated roles to:
View policy code
View simulation inputs and outputs
View sampling results
Without:
Editing policies
Modifying sampling settings
Gaining root-level privileges
Role-Based Controls
New permission(s), e.g.:
policy:read_simulationpolicy:read_sampling
Assignable to custom roles.
Log in to comment and vote
Comments2
Black Breeze
Feb 24
Non-root users can use policy workbench for any policies and samples they have access to. As such, access control is working as intended, and does not limit the usability of the workbench.
As discussed, Spacelift’s RBAC and custom roles only cover write operations, while this is effectively an idempotent read operation - so not a good candidate for extra scopes.
Black Breeze
Feb 24
Thanks for taking the time to write it up, Skye! As discussed internally, the team is investigating overall access logic to the policy workbench, regardless of the new RBAC system.