Skip to main content

Users and access

Invite a user​

In User Management → Users, invite a user with their Email, their Role, and what they may reach. HivePaaS makes an invite link: copy it and send it, or have HivePaaS email it when an email account is set up.

The invited user opens the link, picks a username and a password, and is in. Until then, they show as pending.

Roles​

  • Admin: everything, including users and HivePaaS's own settings.
  • Member: what they are given, and nothing else.

What a member may reach​

A member's access has three parts:

Module Access, for each part of HivePaaS: projects, settings, the cluster, users, and the system. For each, what they may do: Read, Write, Execute (such as deploying, or running a job) and Delete.

Project Access, for each project they may see, and within it, each of its environments: a member given production of a project, and not development, sees and changes that environment's apps only.

Capabilities, two powers given apart:

  • Reveal Secrets: read secrets' values, and mount secrets into apps;
  • Create API keys: make API keys for their account. Taking it away deletes the keys they have.

A user can grant only what they hold themselves.

Access that ends​

Access Expiration ends a user's access at a date: a contractor's, or a temporary helper's.

Security option​

Each user's Security Option says how they sign in:

OptionThe user signs in with
Password Onlya password.
Password 2FAa password and a code from an authenticator app. They set it up on their next sign-in.
Enforce SSOyour single sign-on provider only: their password stops working.

See Sign-in and security.

Disable or remove a user​

Disable User stops a user signing in, and keeps their account and what it did. Remove User deletes the account.

A user who forgot their password can be given a reset link: Reset Password makes one to send them.

API keys​

Each user makes their own API keys, in Your Account → API Keys, for scripts and CI. A key has:

  • a name;
  • what it may do: a key can do less than its user, never more;
  • its capabilities: of its user's, which the key may use - none, unless it is given them;
  • an expiry, a year at most.

The one capability a key can be given is Reveal secrets: reading passwords, private keys and other secrets in the clear, and mounting them into apps. Only a user who holds it can give it. Leave it off for a key that does not need it, and always for one given to an AI assistant: a key without it is refused every secret, even an admin's key. A key made before keys had capabilities has none.

A key cannot make, change or delete keys.

Its secret is shown once, when it is made: HivePaaS keeps only a hash of it. See REST API.