Skip to content

Clearly define the proper permissions for screwdriver admin and user #3421

Description

@yakanechi

What happened:
Screwdriver admins have strong permissions enabling them to delete pipelines which has not permissions within the repository.
This is necessary so that admins can delete the original repository of the pipeline should it be deleted.
On the other hand, if a child pipeline's repository has been deleted within an external configuration pipeline, even an screwdriver admins cannot delete the pipeline via the UI because it cannot be set to inactive in the UI..

Furthermore, whilst possessing powerful privileges, screwdriver admins cannot disable jobs in any pipeline via the UI.
This means they cannot halt problematic jobs that run periodically.

What you expected to happen:

The minimum permissions truly required for screwdriver admins are defined.
The following are related:

How to reproduce it:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions