Assign appropriate permissions to team members to maintain enterprise security while keeping business processes running smoothly. You can configure global permissions for each role or set fine-grained permissions for specific resources, such as pipelines and host groups.
Role permissions
-
Create roles and configure their permissions
Log on to the Alibaba Cloud DevOps Flow console. In the left navigation bar, select . On this page, you can view and configure permissions for each role. By default, the page displays cards for roles such as Owner, Administrator, Member, and External member. You can also add custom roles as needed. To create a custom role, click New Role in the upper-right corner. To edit an existing role, click its card to expand the permission configuration panel, select the permissions to assign, and then click Save.
-
Assign roles to team members
Log on to the Alibaba Cloud DevOps workbench. Go to Organization Management and select . In the member list, assign a role to each member.
Available roles include Owner and Member. To change a member's role, click the dropdown arrow next to the current role.
Pipeline member permissions
Log on to the Alibaba Cloud DevOps Flow console. In the My Pipelines list, click the target pipeline. In the upper-right corner, click the
icon and select Pipeline Settings > Member Permissions. In the member list, you can set permissions for each member.
From the permissions dropdown menu, select All permissions, Run permission, or View permission. You can also click Remove to remove the member from the pipeline, or click Transfer Ownership to make them the new owner.
The following table describes the available permissions.
|
Actions |
Owner permission |
All permissions |
Run permission |
View permission |
|
View pipeline |
Yes |
Yes |
Yes |
Yes |
|
Edit pipeline |
Yes |
Yes |
No |
No |
|
Delete pipeline |
Yes |
Yes |
No |
No |
|
Run pipeline |
Yes |
Yes |
Yes |
No |
|
Add members |
Yes |
Yes |
No |
No |
Pipeline group permissions
Log on to the Alibaba Cloud DevOps Flow console. In the Groups section of the left-side navigation pane, click the target group. On the group page, click the member icon at the top. In the member list, you can set permissions for each member.
The following table describes the available permissions.
|
Actions |
All permissions |
Run permission |
View permission |
|
View pipelines in the group |
Yes |
Yes |
Yes |
|
Edit pipelines in the group |
Yes |
No |
No |
|
Delete pipelines in the group |
Yes |
No |
No |
|
Run pipelines in the group |
Yes |
Yes |
No |
|
Add members to pipelines in the group |
Yes |
No |
No |
|
Add members to the group |
Yes |
No |
No |
Permissions for pipeline groups and individual pipelines follow these rules:
-
If a member's permissions are set at the group level but not for an individual pipeline, the group-level permissions apply to the pipeline.
-
If a member has permissions set at both the group level and the pipeline level, the more permissive of the two scopes applies.
-
To move a pipeline to a group, you must have 'All permissions' for the pipeline.
-
With 'All permissions' for a pipeline group, you can add group members, create pipelines in the group, and move pipelines to the group.
Host group member permissions
Log on to the Alibaba Cloud DevOps Flow console. In the left-side navigation pane, choose . Select the target host group and click Invite in the upper-right corner. In the dialog box that appears, add members and assign a role to each.
The following table describes the available roles and permissions.
|
Actions |
Administrator |
User |
|
Use host group |
Yes |
Yes |
|
Edit host group |
Yes |
No |
|
Delete host group |
Yes |
No |
|
Add members |
Yes |
No |