Support Non Admin Permissions for Account Owner

If a user is an IDP admin or the account owner, they will have admin permissions. Admin permissions should only be used during break glass scenarios/as needed. This is similar to using sudo privileges; today this means that I perform all actions with sudo.

Preferably all users can log in without admin privileges. Login policies can determine if they have elevated space permissions. I picture this as having an “admin” IDP group that is empty most of the time and everyone is in a “All Spacelift Users” group. As needed, a user could request elevated access from the IDP side to be a member of the admin Group. The Spacelift login policy can then grant admin access if the user is in the admin group.

Workaround
No
Problem
Not following Least Privilege Principle

Please authenticate to join the conversation.

Upvoters
Status

⬆️ Gathering votes

Board

💡 Feature Requests

Tags

Access Control

Date

Over 1 year ago

Subscribe to post

Get notified by email when there are changes.