-
Feature Request
-
Resolution: Unresolved
-
Critical
-
None
-
None
-
None
-
None
-
Product / Portfolio Work
-
None
-
False
-
-
None
-
None
-
None
-
-
None
-
-
None
-
None
-
None
1. Proposed title of this feature request
Quay: users can create robot accounts that work across organizations
2. What is the nature and description of the request?
The robot accounts currently can only be created by org admins, who grant the desired permissions. This feature would allow regular users to create robot accounts, and assign the same or fewer permissions the user has, effectively working across organizations. The logs would indicate the user that is linked to the robot account, as it currently does with Applications. The user can select which specific organization and repositories the robot should have what kind of access to, including wildcards for both orgs and repositories. To prevent privilege escalation, the permission boundary of the robot is defined by the permissions of the user. So a superuser can create a robot with global read-only access to all orgs and repos, a regular user can only do that for repos and orgs they have access to.
3. Why does the customer need this? (List the business requirements here)
This would grant more flexibility to users, and the logging would have a better traceability/accountability of the actions performed by robot accounts.
- is duplicated by
-
RFE-7776 Global read only robot account
-
- Closed
-