You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
deploy_component and drop_component are super-user operations (utility/operation_authorization.ts:325, :353). They can be delegated to a role only by operation name (utility/operationPermissions.ts:136-162). An OIDC trust policy names a user and can narrow operations, but it has no project constraint (security/authn/oidc/trustPolicyOperations.ts:119-139).
So a CI identity allowed to deploy PR previews can deploy over any component, including production ones. A PR author can edit the workflow, so the identity's permissions are the only real boundary.
Proposal
A role grant that limits component operations to name patterns, for example:
The guide has to warn that the role applies to the whole cluster, not just my-app-pr-*, and that get_components can expose any component's configuration and files.
This issue is what lets that warning go. The read side matters too: cleanup needs to see its own previews without reading everyone's configuration.
Problem
deploy_componentanddrop_componentare super-user operations (utility/operation_authorization.ts:325,:353). They can be delegated to a role only by operation name (utility/operationPermissions.ts:136-162). An OIDC trust policy names a user and can narrow operations, but it has no project constraint (security/authn/oidc/trustPolicyOperations.ts:119-139).So a CI identity allowed to deploy PR previews can deploy over any component, including production ones. A PR author can edit the workflow, so the identity's permissions are the only real boundary.
Proposal
A role grant that limits component operations to name patterns, for example:
deploy_component,drop_component,get_deploymentandlist_deployments, and filtersget_components.Token operation scope isn't enforced on REST/GraphQL (#2201), so the preview role should hold no table permissions.
Done when
A user holding the grant can deploy and drop
shop-pr-12. They get 403 forshop, for a non-isolated deploy, and for a host outside the suffix.Part of #3042.
Update, 2026-10-07
deploy_component,drop_component,get_componentsandsystem_information.my-app-pr-*, and thatget_componentscan expose any component's configuration and files.