Skip to main content

Users, roles, and permissions

Access in kixctl is verb-level. Every action — instance.create, snapshot.restore, pool.promote, instance.delete, and the rest — is a discrete permission, checked at the point the action runs. A role is a named group of permissions.

Seeded roles

  • super_admin — bypasses every gate.
  • operator — every lifecycle and management verb except the destructive deletes.
  • viewer — read-only.

Managing users

Users are managed under the admin-only Users surface, gated on user.manage. Create a user, assign one or more groups (roles), and grant per-user exception permissions on top of the group where someone needs a single extra verb without a new role. A new user defaults to the lowest group, viewer.

The last-super-admin invariant

At least one super admin must always exist. The last one cannot be deleted or demoted — the delete is refused before any delete machinery runs, so the account and its roles are never partially torn down.

Scope

Access is verb-level across the cluster. Per-object scoping — restricting a user to specific instances — is not part of this tier; it belongs to the enterprise governance direction.