mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-08 01:43:55 +00:00
a1804c8fbe
* docs: comprehensive review and refresh of all documentation pages Reviewed every doc page against the current app state after the v0.38 dashboard redesign. Updated content, fixed inaccuracies, and refreshed all screenshots at 1920x1080. Pages updated: - introduction: expanded feature list to 25 items across 6 subsections - quickstart: fixed docker run command (Docker Hub, auto JWT, COMPOSE_DIR) - configuration: replaced personal paths with generic /home/user/docker - sso-quickstart: fixed Settings navigation reference - sso: added SSO_LDAP_DISPLAY_NAME env var - overview: added 8 missing feature sections (labels, API tokens, schedules, etc.) - dashboard: complete rewrite for new health bar, gauges, stack health table - stack-management: updated for UP/DN indicators, rollback button, split actions - editor: rewritten for two-column layout, inline stats, embedded terminal - resources: updated Quick Clean docs, added network topology and inspect - app-store: updated categories, deploy sheet details, permission gate, settings - openapi.yaml: fixed YAML parsing error on line 1831 Screenshots refreshed: 14 images across 6 feature areas. * docs: review and update observability, console, multi-node, and compatibility pages - Global Observability: fix log format fields, add download button docs, split display limits into memory buffer vs rendered rows, correct settings labels - Host Console: remove internal implementation details per security docs policy, add stack directory behavior, expand header bar docs, remove unverified scrollback claim - Multi-Node: add Compose Directory field, document connection test details panel, fix edit/delete node behavior, simplify token security section, remove internal details - Node Compatibility: add missing self-update capability, remove internal endpoint paths and cache TTL, move from Features to Reference group in navigation - Refresh all screenshots for the redesigned UI (7 images) * docs: review and refresh fleet, remote updates, labels, alerts, routing, and webhooks pages - Fleet View: added node updates modal, container detail, version/update/critical badges, Tags filter - Remote Updates: removed internal details, added capability cross-link, fast polling - Stack Labels: three creation methods, two assignment methods, 10 colors, bulk actions screenshot - Alerts & Notifications: fixed metric labels, added notification popover detail, status banner - Notification Routing: HTTPS requirement, rule card layout, channel terminology fix - Webhooks: corrected license tier to Admiral, matched action labels to UI, removed internal security details, added local-only note - Troubleshooting: centralized entries from remote-updates, stack-labels, notification-routing - Refreshed all screenshots at 1920x1080, removed 11 orphaned images * docs: review and refresh RBAC, user management, and atomic deployments pages - RBAC: added missing Auditor role (5th role), updated permission matrix, fixed license tier references, documented username/password validation rules, self-deletion protection - Atomic Deployments: added "Which operations are protected" section covering webhooks/schedules/app store, removed internal backup path, fixed license tier to Skipper/Admiral - Screenshots: cropped to dialog element per updated strategic cropping guideline, removed 2 orphaned images * docs: review and refresh fleet-wide backups and audit log pages Update fleet-backups page to reflect current inline create form, add scheduled snapshots section, document the detail view and restore dialog, expand RBAC table to all five roles. Update audit log page to document expanded row detail fields, pagination, refresh button, and data retention screenshot. Replace all screenshots with fresh captures at 1920x720. * docs: review and refresh API tokens and private registries pages - API Tokens: clarify Full Admin scope, add Managing tokens section with card details, document revocation confirmation dialog, add usage tracking to security model, refresh screenshot - Private Registries: add Managing registries section with card details and action buttons, document edit behavior, fix URL auto-fill description, remove encryption algorithm name per security policy, fix grammar, refresh both screenshots * docs: review and refresh auto-update policies, scheduled operations, and SSO pages - Auto-Update Policies: document all 8 table columns, expand action buttons, add "All Stacks" wildcard option, fix field labels, add CSV export and pagination details, refresh screenshots - Scheduled Operations: fix System Prune target description, add Task List table columns, restructure create dialog fields with action-specific annotations, rewrite execution history with column table, refresh screenshots - SSO: remove encryption algorithm name per security policy, add LDAP and OIDC configuration field tables, document provider card controls (Save, Test Connection, Remove, Active badge), refresh screenshots - Move SSO troubleshooting entries to centralized troubleshooting page * docs: review and refresh licensing & billing page Update upgrade card feature lists to match actual tier gating (Skipper: fleet view, webhooks, labels, atomic deployments, backups, auto-update policies; Admiral: scoped RBAC, SSO, audit log, host console, API tokens, private registries, scheduled operations). Add flex layout to align upgrade card buttons at the bottom. Replace stale screenshot with fresh community and active license captures. Add feature breakdown subsection and profile menu billing shortcut to docs. * docs: review and refresh settings reference and security advisories pages Settings Reference: add 5 missing sections (SSO, API Tokens, Registries, Labels, Routing), expand Users from 2 to 5 roles, fix System Limits and Developer field labels to match UI, restructure Developer into Streaming and Data Retention sub-tables, update App Store and Support sections, refresh overview screenshot. Security Advisories: restructure into versioned sections (v0.25.x hardening and v0.19-v0.24 CVE remediation), expand from 3 bullet points to 10 specific improvements, fix GitHub URL from SaelixCode to AnsoCode, redact internal details per security docs policy. Remove "Sencho Pro" product name from all three pages, replaced with tier names (Community, Skipper, Admiral). * docs: review and refresh troubleshooting page, remove architecture and development guides - Rewrote forgotten password section to remove exposed SQL and table names - Updated all Settings navigation paths to Profile > Settings > X - Fixed network topology from "tab" to "view mode", added Pro license note - Updated Prune Networks to current "Prune Dead Networks" label - Corrected update check cooldown from vague to 2 minutes - Consolidated two network creation error sections into one - Removed hardcoded version reference (v0.34.0) - Replaced em dashes throughout - Deleted architecture.mdx (exposes internal implementation details) - Deleted development.mdx (contributor guide belongs in repo, not public docs) - Removed both pages from docs.json navigation * docs: review and refresh operations pages (backup, upgrade, self-hosting, troubleshooting) Backup & Restore: - Added missing encryption.key to all backup/restore procedures - Added Warning about restoring db without matching encryption key - Added cross-reference to Fleet-Wide Backups for paid tiers - Removed false claim about no built-in backup scheduler - Updated cron example to include encryption key copy Upgrading Sencho: - Removed internal migration details (table names, column specs, encryption algorithm) - Replaced with high-level migration summary per security docs policy - Added encryption.key to pre-upgrade backup command - Updated version pinning example from 0.25.3 to 0.38.0 - Added Remote Updates cross-reference for Skipper/Admiral users Self-Hosting Best Practices: - Removed JWT_SECRET from env var table (auto-generated, not an env var) - Removed PORT from env var table (hardcoded to 3000, not configurable) - Added API_RATE_LIMIT to env var table (actually exists in code) - Fixed listen port description from "configurable" to "fixed" - Updated resource recommendations based on measured footprint audit - Removed su-exec reference (internal implementation detail) - Upgraded data directory Note to Warning with file names Troubleshooting: - Fixed "Pro features" heading to "Paid features" with correct tier names
121 lines
5.9 KiB
Plaintext
121 lines
5.9 KiB
Plaintext
---
|
|
title: RBAC & User Management
|
|
description: Role-based access control for Sencho - manage admin, viewer, deployer, node admin, and auditor accounts with scoped permissions.
|
|
---
|
|
|
|
<Note>
|
|
Multi-user support requires a **Sencho Skipper** or **Admiral** license. Community Edition supports a single admin account only. Intermediate roles (Deployer, Node Admin, Auditor) and scoped permissions require **Admiral**.
|
|
</Note>
|
|
|
|
Sencho supports role-based access control with five distinct roles. **Admin** and **Viewer** are available on all Pro tiers, while **Deployer**, **Node Admin**, and **Auditor** are exclusive to Admiral.
|
|
|
|
## Roles
|
|
|
|
| Role | Description | Tier |
|
|
|------|-------------|------|
|
|
| **Admin** | Full access to all features: deploy, edit, manage users, configure nodes, and system settings | Skipper+ |
|
|
| **Viewer** | Read-only access to dashboards, logs, stats, and file contents | Skipper+ |
|
|
| **Deployer** | Can deploy, restart, stop, and start stacks, but cannot edit compose files, delete stacks, or access system settings | Admiral |
|
|
| **Node Admin** | Full stack and node management within their scope, but no access to system settings, users, or license management | Admiral |
|
|
| **Auditor** | Read-only access like Viewer, plus access to the audit log | Admiral |
|
|
|
|
### Permission matrix
|
|
|
|
| Action | Admin | Node Admin | Deployer | Auditor | Viewer |
|
|
|--------|-------|------------|----------|---------|--------|
|
|
| View stacks, logs, stats | Yes | Yes | Yes | Yes | Yes |
|
|
| Deploy / restart / stop / start stacks | Yes | Yes | Yes | No | No |
|
|
| Edit compose and `.env` files | Yes | Yes | No | No | No |
|
|
| Create and delete stacks | Yes | Yes | No | No | No |
|
|
| View nodes | Yes | Yes | Yes | Yes | Yes |
|
|
| Add / edit / delete nodes | Yes | Yes | No | No | No |
|
|
| Audit log | Yes | No | No | Yes | No |
|
|
| System settings | Yes | No | No | No | No |
|
|
| User management | Yes | No | No | No | No |
|
|
| License management | Yes | No | No | No | No |
|
|
| Webhooks | Yes | No | No | No | No |
|
|
| API tokens | Yes | No | No | No | No |
|
|
| Host console | Yes | No | No | No | No |
|
|
|
|
## Managing users
|
|
|
|
Go to **Settings > Users** to view the user list. The table shows each user's username, role badge, creation date, and action buttons.
|
|
|
|
<Frame>
|
|
<img src="/images/rbac/users-list.png" alt="User Management showing the users table with username, role, and creation date" />
|
|
</Frame>
|
|
|
|
From the user table you can:
|
|
|
|
- **Edit** a user by clicking the pencil icon
|
|
- **Delete** a user by clicking the trash icon (with a confirmation dialog)
|
|
|
|
You cannot delete your own account. The delete button is disabled for the currently logged-in user.
|
|
|
|
### Creating a user
|
|
|
|
Click **Add User** to open the creation form.
|
|
|
|
<Frame>
|
|
<img src="/images/rbac/user-create-form.png" alt="New User form with Username, Role, Password, and Confirm Password fields" />
|
|
</Frame>
|
|
|
|
| Field | Description |
|
|
|-------|-------------|
|
|
| **Username** | At least 3 characters. Letters, numbers, underscores, and hyphens only. |
|
|
| **Role** | Select from the available roles (see below) |
|
|
| **Password** | At least 8 characters |
|
|
| **Confirm Password** | Must match the password field |
|
|
|
|
On Admiral, all five roles appear in the role selector. On Skipper, only Admin and Viewer are available.
|
|
|
|
<Frame>
|
|
<img src="/images/rbac/role-selector-dropdown.png" alt="Role selector dropdown showing all five roles on Admiral" />
|
|
</Frame>
|
|
|
|
### Editing a user
|
|
|
|
Click the pencil icon on a user row to edit. You can change the username, role, and optionally set a new password. Leave the password fields blank to keep the existing password.
|
|
|
|
## Scoped permissions
|
|
|
|
<Note>
|
|
Scoped permissions require an **Admiral** license.
|
|
</Note>
|
|
|
|
Roles can be scoped to specific stacks or nodes. This lets you grant a user elevated permissions on particular resources without giving them broad access.
|
|
|
|
Scoped permissions **add to** the user's global role. They never reduce it. A user with a global Viewer role plus a scoped Deployer assignment on the "my-app" stack can deploy "my-app" but has read-only access to everything else.
|
|
|
|
When editing a user on Admiral, a **Scoped Permissions** section appears below the user form. From there you can:
|
|
|
|
1. **View** the user's current scoped assignments, each showing the role badge, resource type, and resource name
|
|
2. **Add** a new scope by selecting a role (Deployer, Node Admin, or Admin), resource type (Stack or Node), and the specific resource
|
|
3. **Remove** an existing scope with the trash icon
|
|
|
|
### Example scenarios
|
|
|
|
- A **Viewer** with a scoped **Deployer** assignment on the `frontend` stack can deploy, restart, and stop only that stack.
|
|
- A **Deployer** with a scoped **Node Admin** assignment on node "staging-server" can manage stacks and nodes on that server, plus deploy globally.
|
|
- A **Node Admin** without any scoped assignments can manage all stacks and nodes but has no access to system settings.
|
|
|
|
## SSO auto-provisioning
|
|
|
|
With an Admiral license, users can also be created automatically when they log in via SSO (LDAP, Google, GitHub, or Okta). SSO users appear in the Users list alongside local accounts and are assigned a role based on identity provider group membership or claim mapping.
|
|
|
|
SSO users cannot log in with a password; they must always authenticate through their identity provider. After SSO provisioning, an admin can add scoped permissions to SSO users just like local accounts.
|
|
|
|
To set up identity provider authentication, see [SSO Authentication](/features/sso).
|
|
|
|
## Migration from single-admin setup
|
|
|
|
When you upgrade to a Skipper or Admiral license, your existing single-admin credentials are automatically migrated. No manual action is required; your login continues to work as before, and your account is assigned the Admin role.
|
|
|
|
## Account limits by tier
|
|
|
|
| Tier | Admin accounts | Non-admin accounts | Intermediate roles | Scoped permissions |
|
|
|------|---------------|-------------------|-------------------|-------------------|
|
|
| **Community** | 1 | 0 | No | No |
|
|
| **Skipper** | 1 | 3 | No | No |
|
|
| **Admiral** | Unlimited | Unlimited | Yes | Yes |
|