Reference

Permissions reference

See the cloud roles and permissions each Zaysa feature needs.

About 8 minutes

To see what your connection has, use Check permissions.

The default connection setup grants read access for scans, costs and supported history views. It uses the roles listed below for each cloud. Billing exports in another project or storage account, team access, deploy jobs and changes to resources can need extra grants. Write features are always opt in and are never part of the default connection setup.

Each capability lists the identity that makes the call. Grant its roles to that identity at the scope where Zaysa reads or changes resources. If an action depends on a CLI command, model choice or API endpoint at runtime, the exact permission is still being established and the feature is marked as needing separate setup.

AWS

Default connection grants: ReadOnlyAccess

Cloud History

PurposeAccessIdentityDefault setupGrantWithout it
Reads provider activity so you can see what changed.ReadConnected cloud accountIncluded
ReadOnlyAccess
Show 1 exact permissions
cloudtrail:LookupEvents smallest listed role: ReadOnlyAccess
Cloud events and change history are unavailable.

Billing export

PurposeAccessIdentityDefault setupGrantWithout it
Reads detailed billing data and export tables.ReadConnected cloud accountIncluded
ReadOnlyAccess
Show 3 exact permissions
ce:GetCostAndUsageWithResources smallest listed role: ReadOnlyAccess
s3:GetObject smallest listed role: ReadOnlyAccess
s3:ListBucket smallest listed role: ReadOnlyAccess
Detailed invoiced costs cannot be shown.

Resource Explorer

PurposeAccessIdentityDefault setupGrantWithout it
Lists AWS Resource Explorer resources during discovery.ReadConnected cloud accountExtra step
Custom IAM allow
Show 1 exact permissions
resource-explorer-2:ListResources smallest listed role: Custom IAM allow
Resource Explorer results are unavailable.

Cloud account setup

PurposeAccessIdentityDefault setupGrantWithout it
Creates the optional AWS Resource Explorer index.WriteConnected cloud accountExtra step
Custom IAM allow
Show 1 exact permissions
resource-explorer-2:CreateIndex smallest listed role: Custom IAM allow
The optional Resource Explorer index is not created.

Kubernetes visibility

PurposeAccessIdentityDefault setupGrantWithout it
Lists clusters and workload resources.ReadConnected cloud accountIncluded
ReadOnlyAccess
Show 4 exact permissions
eks:DescribeCluster smallest listed role: ReadOnlyAccess
eks:DescribeNodegroup smallest listed role: ReadOnlyAccess
eks:ListClusters smallest listed role: ReadOnlyAccess
eks:ListNodegroups smallest listed role: ReadOnlyAccess
Cluster resources are missing from visibility views.

Costs and scans

PurposeAccessIdentityDefault setupGrantWithout it
Reads resources and usage for scheduled scans and cost views.ReadConnected cloud accountIncluded
ReadOnlyAccess
Show 132 exact permissions
acm:ListCertificates smallest listed role: ReadOnlyAccess
apigateway:GET smallest listed role: ReadOnlyAccess
athena:GetWorkGroup smallest listed role: ReadOnlyAccess
athena:ListWorkGroups smallest listed role: ReadOnlyAccess
autoscaling:DescribeAutoScalingGroups smallest listed role: ReadOnlyAccess
backup:ListBackupVaults smallest listed role: ReadOnlyAccess
batch:DescribeComputeEnvironments smallest listed role: ReadOnlyAccess
batch:DescribeJobQueues smallest listed role: ReadOnlyAccess
ce:GetCostAndUsage smallest listed role: ReadOnlyAccess
cloudformation:DescribeStacks smallest listed role: ReadOnlyAccess
cloudfront:ListDistributions smallest listed role: ReadOnlyAccess
cloudtrail:DescribeTrails smallest listed role: ReadOnlyAccess
cloudtrail:GetTrailStatus smallest listed role: ReadOnlyAccess
cloudwatch:DescribeAlarms smallest listed role: ReadOnlyAccess
cloudwatch:GetMetricStatistics smallest listed role: ReadOnlyAccess
codebuild:BatchGetProjects smallest listed role: ReadOnlyAccess
codebuild:ListProjects smallest listed role: ReadOnlyAccess
dms:DescribeEndpoints smallest listed role: ReadOnlyAccess
dms:DescribeReplicationInstances smallest listed role: ReadOnlyAccess
dynamodb:DescribeTable smallest listed role: ReadOnlyAccess
dynamodb:ListTables smallest listed role: ReadOnlyAccess
ec2:DescribeAddresses smallest listed role: ReadOnlyAccess
ec2:DescribeFleets smallest listed role: ReadOnlyAccess
ec2:DescribeImages smallest listed role: ReadOnlyAccess
ec2:DescribeInstances smallest listed role: ReadOnlyAccess
ec2:DescribeInternetGateways smallest listed role: ReadOnlyAccess
ec2:DescribeManagedPrefixLists smallest listed role: ReadOnlyAccess
ec2:DescribeNatGateways smallest listed role: ReadOnlyAccess
ec2:DescribeNetworkAcls smallest listed role: ReadOnlyAccess
ec2:DescribeNetworkInterfaces smallest listed role: ReadOnlyAccess
ec2:DescribeRegions smallest listed role: ReadOnlyAccess
ec2:DescribeRouteTables smallest listed role: ReadOnlyAccess
ec2:DescribeSecurityGroupRules smallest listed role: ReadOnlyAccess
ec2:DescribeSecurityGroups smallest listed role: ReadOnlyAccess
ec2:DescribeSnapshots smallest listed role: ReadOnlyAccess
ec2:DescribeSubnets smallest listed role: ReadOnlyAccess
ec2:DescribeTransitGatewayAttachments smallest listed role: ReadOnlyAccess
ec2:DescribeTransitGateways smallest listed role: ReadOnlyAccess
ec2:DescribeVolumes smallest listed role: ReadOnlyAccess
ec2:DescribeVpcEndpoints smallest listed role: ReadOnlyAccess
ec2:DescribeVpcPeeringConnections smallest listed role: ReadOnlyAccess
ec2:DescribeVpcs smallest listed role: ReadOnlyAccess
ec2:DescribeVpnConnections smallest listed role: ReadOnlyAccess
ec2:DescribeVpnGateways smallest listed role: ReadOnlyAccess
ec2:GetManagedPrefixListEntries smallest listed role: ReadOnlyAccess
ecr:DescribeRepositories smallest listed role: ReadOnlyAccess
ecr:ListImages smallest listed role: ReadOnlyAccess
ecs:DescribeClusters smallest listed role: ReadOnlyAccess
ecs:DescribeServices smallest listed role: ReadOnlyAccess
ecs:DescribeTaskDefinition smallest listed role: ReadOnlyAccess
ecs:DescribeTasks smallest listed role: ReadOnlyAccess
ecs:ListClusters smallest listed role: ReadOnlyAccess
ecs:ListServices smallest listed role: ReadOnlyAccess
ecs:ListTasks smallest listed role: ReadOnlyAccess
eks:DescribeFargateProfile smallest listed role: ReadOnlyAccess
eks:ListFargateProfiles smallest listed role: ReadOnlyAccess
elasticache:DescribeCacheClusters smallest listed role: ReadOnlyAccess
elasticache:DescribeCacheSubnetGroups smallest listed role: ReadOnlyAccess
elasticache:DescribeReplicationGroups smallest listed role: ReadOnlyAccess
elasticache:DescribeServerlessCaches smallest listed role: ReadOnlyAccess
elasticbeanstalk:DescribeApplications smallest listed role: ReadOnlyAccess
elasticbeanstalk:DescribeEnvironments smallest listed role: ReadOnlyAccess
elasticfilesystem:DescribeFileSystems smallest listed role: ReadOnlyAccess
elasticfilesystem:DescribeMountTargetSecurityGroups smallest listed role: ReadOnlyAccess
elasticfilesystem:DescribeMountTargets smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeInstanceHealth smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeListeners smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeLoadBalancers smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeRules smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeTags smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeTargetGroups smallest listed role: ReadOnlyAccess
elasticloadbalancing:DescribeTargetHealth smallest listed role: ReadOnlyAccess
es:DescribeDomain smallest listed role: ReadOnlyAccess
es:DescribeDomains smallest listed role: ReadOnlyAccess
es:ListDomainNames smallest listed role: ReadOnlyAccess
events:ListEventBuses smallest listed role: ReadOnlyAccess
events:ListRules smallest listed role: ReadOnlyAccess
events:ListTargetsByRule smallest listed role: ReadOnlyAccess
freetier:GetFreeTierUsage smallest listed role: ReadOnlyAccess
glue:GetDatabases smallest listed role: ReadOnlyAccess
glue:GetTables smallest listed role: ReadOnlyAccess
iam:GenerateCredentialReport smallest listed role: ReadOnlyAccess
iam:GetAccountAuthorizationDetails smallest listed role: ReadOnlyAccess
iam:GetAccountPasswordPolicy smallest listed role: ReadOnlyAccess
iam:GetAccountSummary smallest listed role: ReadOnlyAccess
iam:GetCredentialReport smallest listed role: ReadOnlyAccess
iam:ListAccessKeys smallest listed role: ReadOnlyAccess
iam:ListAttachedUserPolicies smallest listed role: ReadOnlyAccess
iam:ListMFADevices smallest listed role: ReadOnlyAccess
iam:ListUsers smallest listed role: ReadOnlyAccess
kafka:ListClustersV2 smallest listed role: ReadOnlyAccess
kinesis:DescribeStreamSummary smallest listed role: ReadOnlyAccess
kinesis:ListStreams smallest listed role: ReadOnlyAccess
kms:DescribeKey smallest listed role: ReadOnlyAccess
kms:ListKeys smallest listed role: ReadOnlyAccess
lambda:ListEventSourceMappings smallest listed role: ReadOnlyAccess
lambda:ListFunctions smallest listed role: ReadOnlyAccess
logs:DescribeLogGroups smallest listed role: ReadOnlyAccess
memorydb:DescribeClusters smallest listed role: ReadOnlyAccess
memorydb:DescribeSubnetGroups smallest listed role: ReadOnlyAccess
pricing:GetProducts smallest listed role: ReadOnlyAccess
rds:DescribeDBClusters smallest listed role: ReadOnlyAccess
rds:DescribeDBInstances smallest listed role: ReadOnlyAccess
rds:DescribeDBSnapshots smallest listed role: ReadOnlyAccess
rds:DescribeDBSubnetGroups smallest listed role: ReadOnlyAccess
redshift-serverless:ListNamespaces smallest listed role: ReadOnlyAccess
redshift-serverless:ListWorkgroups smallest listed role: ReadOnlyAccess
redshift:DescribeClusterSubnetGroups smallest listed role: ReadOnlyAccess
redshift:DescribeClusters smallest listed role: ReadOnlyAccess
resource-explorer-2:ListIndexes smallest listed role: ReadOnlyAccess
resource-explorer-2:Search smallest listed role: ReadOnlyAccess
route53:GetHostedZone smallest listed role: ReadOnlyAccess
route53:ListHostedZones smallest listed role: ReadOnlyAccess
route53:ListResourceRecordSets smallest listed role: ReadOnlyAccess
s3:GetBucketAcl smallest listed role: ReadOnlyAccess
s3:GetBucketLifecycleConfiguration smallest listed role: ReadOnlyAccess
s3:GetBucketLocation smallest listed role: ReadOnlyAccess
s3:GetBucketPolicyStatus smallest listed role: ReadOnlyAccess
s3:GetPublicAccessBlock smallest listed role: ReadOnlyAccess
s3:ListBuckets smallest listed role: ReadOnlyAccess
sagemaker:ListEndpoints smallest listed role: ReadOnlyAccess
sagemaker:ListNotebookInstances smallest listed role: ReadOnlyAccess
secretsmanager:ListSecrets smallest listed role: ReadOnlyAccess
sns:GetTopicAttributes smallest listed role: ReadOnlyAccess
sns:ListSubscriptions smallest listed role: ReadOnlyAccess
sns:ListTopics smallest listed role: ReadOnlyAccess
sqs:GetQueueAttributes smallest listed role: ReadOnlyAccess
sqs:ListQueues smallest listed role: ReadOnlyAccess
states:DescribeStateMachine smallest listed role: ReadOnlyAccess
states:ListStateMachines smallest listed role: ReadOnlyAccess
tag:GetResources smallest listed role: ReadOnlyAccess
workspaces:DescribeWorkspaces smallest listed role: ReadOnlyAccess
Those resources or costs can be missing from scans.

AutoStopping

PurposeAccessIdentityDefault setupGrantWithout it
Stops and starts selected idle compute resources.WriteConnected cloud accountExtra step
Custom IAM allow
Show 5 exact permissions
autoscaling:CreateOrUpdateTags smallest listed role: Custom IAM allow
autoscaling:SetDesiredCapacity smallest listed role: Custom IAM allow
autoscaling:UpdateAutoScalingGroup smallest listed role: Custom IAM allow
ec2:StartInstances smallest listed role: Custom IAM allow
ec2:StopInstances smallest listed role: Custom IAM allow
Automatic stopping and restart fail.

Autopilot fixes

PurposeAccessIdentityDefault setupGrantWithout it
Applies approved changes to cloud resources.WriteConnected cloud accountExtra step
Custom IAM allow
Show 3 exact permissions
ec2:RevokeSecurityGroupIngress smallest listed role: Custom IAM allow
rds:ModifyDBInstance smallest listed role: Custom IAM allow
s3:PutPublicAccessBlock smallest listed role: Custom IAM allow
Approved fixes cannot be applied.

CI/CD and deploy

PurposeAccessIdentityDefault setupGrantWithout it
Runs deployment and infrastructure operations through the CI runner.WriteCI runnerExtra step
Custom IAM allow
PowerUserAccess
Show 7 exact permissions
dynamodb:CreateTable smallest listed role: Custom IAM allow
dynamodb:DeleteItem smallest listed role: Custom IAM allow
dynamodb:PutItem smallest listed role: Custom IAM allow
s3:CreateBucket smallest listed role: Custom IAM allow
s3:DeleteObject smallest listed role: Custom IAM allow
s3:PutBucketVersioning smallest listed role: Custom IAM allow
s3:PutObject smallest listed role: Custom IAM allow
Deployments and infrastructure jobs fail.

Beam team access

PurposeAccessIdentityDefault setupGrantWithout it
Creates and revokes short lived human access grants.WriteBeam identityExtra step
Custom IAM allow
ReadOnlyAccess
Show 12 exact permissions
elasticache:CreateUser smallest listed role: Custom IAM allow
elasticache:DeleteUser smallest listed role: Custom IAM allow
elasticache:DescribeUserGroups smallest listed role: ReadOnlyAccess
elasticache:ModifyUserGroup smallest listed role: Custom IAM allow
iam:GetRole smallest listed role: ReadOnlyAccess
iam:GetRolePolicy smallest listed role: ReadOnlyAccess
iam:PutRolePolicy smallest listed role: Custom IAM allow
memorydb:CreateUser smallest listed role: Custom IAM allow
memorydb:DeleteUser smallest listed role: Custom IAM allow
memorydb:DescribeACLs smallest listed role: ReadOnlyAccess
memorydb:UpdateACL smallest listed role: Custom IAM allow
sts:AssumeRole smallest listed role: Custom IAM allow
Beam cannot mint or revoke those grants.

GitOps: install Argo CD

PurposeAccessIdentityDefault setupGrantWithout it
Installs Argo CD into a cluster so it can deploy your apps from Git.WriteDeploy identityExtra step
EKS access entry: AmazonEKSClusterAdminPolicy (cluster scope)
Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster.

Permissions still being resolved

76 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.

Show call sites
  • lib/autopilot/cloud-exec.ts:731: approvedFixes. The inventory could not establish the exact provider action for this call.
  • lib/delivery/generate-jenkinsfile.ts:1097: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1098: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1100: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1101: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1110: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1119: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1120: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1131: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1132: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1144: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1150: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1151: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1164: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1739: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1771: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1860: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1865: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1868: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1891: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1896: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1898: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:2156: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:621: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:785: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:906: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:908: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:920: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:922: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:925: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:931: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3068: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3069: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3129: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3130: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3265: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3363: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3450: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3579: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3603: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3604: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3715: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3719: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3737: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4478: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4479: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4501: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5104: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5258: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5342: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5346: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5352: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5878: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5904: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5907: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5910: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5917: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6510: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6511: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6512: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6603: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6604: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6610: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6611: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6676: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7275: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7280: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7284: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7290: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7403: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8257: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8855: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/scanner/aws.ts:4140: scheduledScans. Identity check needs no IAM allow.
  • lib/scanner/validate-live-credentials.ts:90: scheduledScans. Identity check needs no IAM allow.
  • lib/cloud-map/aws/build.ts:79: cloudMap. Identity check needs no IAM allow.

Google Cloud

Default connection grants: roles/cloudasset.viewer, roles/compute.viewer, roles/monitoring.viewer, roles/recommender.viewer, roles/logging.viewer, roles/browser, roles/bigquery.jobUser, roles/bigquery.dataViewer, roles/container.viewer, roles/cloudsql.viewer, roles/storage.bucketViewer, roles/run.viewer, roles/cloudfunctions.viewer, roles/pubsub.viewer, roles/artifactregistry.reader, roles/redis.viewer, roles/file.viewer

roles/bigquery.jobUser lets Zaysa read the query jobs it creates for billing. The scanner list calls use service-specific viewer roles, including roles/storage.bucketViewer for bucket listing. Additional viewer roles remain for dynamic scanner calls.

Cloud History

PurposeAccessIdentityDefault setupGrantWithout it
Reads provider activity so you can see what changed.ReadConnected cloud accountIncluded
roles/logging.viewer
Show 1 exact permissions
logging.logEntries.list smallest listed role: roles/logging.viewer
Cloud events and change history are unavailable.

Billing export

PurposeAccessIdentityDefault setupGrantWithout it
Reads detailed billing data and export tables.ReadConnected cloud accountIncluded
roles/bigquery.jobUser
roles/bigquery.dataViewer
Show 3 exact permissions
bigquery.jobs.create smallest listed role: roles/bigquery.jobUser
bigquery.jobs.get grant: roles/bigquery.jobUser (own jobs only)
bigquery.tables.getData smallest listed role: roles/bigquery.dataViewer
Detailed invoiced costs cannot be shown.

Kubernetes visibility

PurposeAccessIdentityDefault setupGrantWithout it
Lists clusters and workload resources.ReadConnected cloud accountIncluded
roles/container.viewer
Show 1 exact permissions
container.clusters.list smallest listed role: roles/container.viewer
Cluster resources are missing from visibility views.

Costs and scans

PurposeAccessIdentityDefault setupGrantWithout it
Reads resources and usage for scheduled scans and cost views.ReadConnected cloud accountIncluded
Show 13 roles
roles/artifactregistry.reader
roles/cloudasset.viewer
roles/cloudfunctions.viewer
roles/cloudsql.viewer
roles/file.viewer
roles/pubsub.viewer
roles/redis.viewer
roles/run.viewer
roles/storage.bucketViewer
roles/compute.viewer
roles/monitoring.viewer
roles/recommender.viewer
roles/browser
Show 10 exact permissions
artifactregistry.repositories.list smallest listed role: roles/artifactregistry.reader
cloudasset.assets.searchAllIamPolicies smallest listed role: roles/cloudasset.viewer
cloudasset.assets.searchAllResources smallest listed role: roles/cloudfunctions.viewer; default uses roles/cloudasset.viewer
cloudfunctions.functions.list smallest listed role: roles/cloudfunctions.viewer
cloudsql.instances.list smallest listed role: roles/cloudsql.viewer
file.instances.list smallest listed role: roles/file.viewer
pubsub.topics.list smallest listed role: roles/pubsub.viewer
redis.instances.list smallest listed role: roles/redis.viewer
run.services.list smallest listed role: roles/run.viewer
storage.buckets.list smallest listed role: roles/storage.bucketViewer
Those resources or costs can be missing from scans.

AutoStopping

PurposeAccessIdentityDefault setupGrantWithout it
Stops and starts selected idle VM instances.WriteConnected cloud accountExtra step
roles/compute.viewer
Custom IAM role
Show 3 exact permissions
compute.instances.get smallest listed role: roles/compute.viewer
compute.instances.start smallest listed role: Custom IAM role
compute.instances.stop smallest listed role: Custom IAM role
Automatic stopping and restart fail.

Autopilot fixes

PurposeAccessIdentityDefault setupGrantWithout it
Applies approved changes to cloud resources.WriteConnected cloud accountExtra step
roles/compute.viewer
Custom IAM role
Show 2 exact permissions
compute.firewalls.get smallest listed role: roles/compute.viewer
compute.firewalls.update smallest listed role: Custom IAM role
Approved fixes cannot be applied.

Beam team access

PurposeAccessIdentityDefault setupGrantWithout it
Creates and revokes short lived human access grants.WriteDeploy identityExtra step
roles/iam.serviceAccountAdmin
roles/iam.serviceAccountTokenCreator
roles/iam.securityReviewer
roles/resourcemanager.projectIamAdmin
Show 7 exact permissions
iam.serviceAccounts.create smallest listed role: roles/iam.serviceAccountAdmin
iam.serviceAccounts.delete smallest listed role: roles/iam.serviceAccountAdmin
iam.serviceAccounts.disable smallest listed role: roles/iam.serviceAccountAdmin
iam.serviceAccounts.getAccessToken smallest listed role: roles/iam.serviceAccountTokenCreator
iam.serviceAccounts.getIamPolicy smallest listed role: roles/iam.securityReviewer
iam.serviceAccounts.setIamPolicy smallest listed role: roles/iam.serviceAccountAdmin
resourcemanager.projects.setIamPolicy smallest listed role: roles/resourcemanager.projectIamAdmin
Beam cannot mint or revoke those grants.

Autopilot insights

PurposeAccessIdentityDefault setupGrantWithout it
Reads cloud signals for findings and database checks.ReadConnected cloud accountExtra step
The exact grant depends on the operation.
Some findings or database signals are unavailable.

CI/CD and deploy

PurposeAccessIdentityDefault setupGrantWithout it
Runs deployment and infrastructure operations through the CI runner.WriteCI runnerExtra step
Show 41 roles
roles/container.admin
roles/run.admin
roles/compute.admin
roles/cloudfunctions.admin
roles/artifactregistry.admin
roles/storage.admin
roles/cloudsql.admin
roles/serviceusage.serviceUsageAdmin
roles/iam.serviceAccountAdmin
roles/iam.serviceAccountUser
roles/iap.tunnelResourceAccessor
roles/compute.osAdminLogin
roles/pubsub.admin
roles/bigquery.admin
roles/secretmanager.admin
roles/dns.admin
roles/monitoring.admin
roles/logging.admin
roles/cloudkms.admin
roles/cloudscheduler.admin
roles/cloudtasks.admin
roles/workflows.admin
roles/spanner.admin
roles/bigtable.admin
roles/alloydb.admin
roles/redis.admin
roles/memorystore.admin
roles/memcache.admin
roles/file.editor
roles/datastore.owner
roles/dataproc.admin
roles/dataflow.admin
roles/composer.admin
roles/cloudbuild.builds.editor
roles/aiplatform.admin
roles/notebooks.admin
roles/certificatemanager.editor
roles/binaryauthorization.policyEditor
roles/dataplex.admin
roles/resourcemanager.tagAdmin
roles/iam.workloadIdentityPoolAdmin
Deployments and infrastructure jobs fail.

GitOps: install Argo CD

PurposeAccessIdentityDefault setupGrantWithout it
Installs Argo CD into a cluster so it can deploy your apps from Git.WriteDeploy identityExtra step
roles/container.admin
Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster.

Cloud Map

PurposeAccessIdentityDefault setupGrantWithout it
Reads resource configuration and the effective firewall of each VPC network to draw the Cloud Map.ReadConnected cloud accountIncluded
roles/cloudasset.viewer
roles/compute.viewer
Show 3 exact permissions
cloudasset.assets.listResource smallest listed role: roles/cloudasset.viewer
compute.networks.getEffectiveFirewalls smallest listed role: roles/compute.viewer
compute.networks.getRegionEffectiveFirewalls smallest listed role: roles/compute.viewer
The Cloud Map shows resources without configured lines, can-reach lines or internet exposure.

Permissions still being resolved

68 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.

Show call sites
  • lib/cloud-accounts/verify-deploy-permissions.ts:142: Other cloud operation. The inventory could not establish the exact provider action for this call.
  • lib/pricing/fetch-gcp.ts:73: Other cloud operation. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/cloud-exec.ts:409: approvedFixes. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cert-expiry.ts:631: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-link.ts:547: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals-families.ts:875: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals-families.ts:987: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals.ts:1403: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals.ts:1416: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals.ts:1443: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals.ts:1476: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals.ts:1511: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/db-cloud-signals.ts:1543: databases. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/ai-diagnose.ts:186: findings. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/cloud-fix.ts:306: findings. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/cloud-regions.ts:72: findings. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/cloud-repair.ts:97: findings. The inventory could not establish the exact provider action for this call.
  • lib/autopilot/vm-cloud-state.ts:248: findings. The inventory could not establish the exact provider action for this call.
  • lib/delivery/generate-jenkinsfile.ts:1220: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1230: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1236: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1253: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1264: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1363: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1982: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1995: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:681: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:683: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:698: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:725: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:75: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:951: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3475: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3640: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3644: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3779: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3801: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4489: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5116: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5492: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5512: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5534: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5957: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:627: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7115: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7120: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7130: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7556: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7595: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7599: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7602: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7608: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7693: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8862: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/pr-gates/pricing/gcp-live.ts:106: prCostGates. The inventory could not establish the exact provider action for this call.
  • lib/pr-gates/pricing/gcp-live.ts:160: prCostGates. The inventory could not establish the exact provider action for this call.
  • lib/ai/deploy/gcp-required-apis.ts:70: stacks. The inventory could not establish the exact provider action for this call.
  • lib/deploy/unmanaged-scan.ts:958: stacks. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp-monitoring.ts:174: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp-monitoring.ts:62: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp-recommender.ts:55: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp-storage-softdelete.ts:66: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp-vm-pricing.ts:226: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp.ts:1939: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp.ts:1974: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/gcp.ts:422: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/kubernetes/pricing/sources/gcp.ts:149: kubernetes. The inventory could not establish the exact provider action for this call.

Azure

Default connection grants: Reader, Cost Management Reader

Microsoft Graph Directory.Read.All is an Entra API permission, not an Azure RBAC role. It is optional: without it, principal IDs appear instead of names. Reading billing export blobs needs Storage Blob Data Reader at the storage account.

Cloud History

PurposeAccessIdentityDefault setupGrantWithout it
Reads provider activity so you can see what changed.ReadConnected cloud accountIncluded
Reader
Show 1 exact permissions
Microsoft.Insights/eventtypes/management/values/read smallest listed role: Reader
Cloud events and change history are unavailable.

Billing export storage

PurposeAccessIdentityDefault setupGrantWithout it
Reads an Azure billing export from blob storage.ReadConnected cloud accountExtra step
Storage Blob Data Reader
Show 1 exact permissions
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read smallest listed role: Storage Blob Data Reader
Blob based billing exports cannot be imported.

Billing export

PurposeAccessIdentityDefault setupGrantWithout it
Reads detailed billing data and export tables.ReadConnected cloud accountIncluded
Cost Management Reader
Show 1 exact permissions
Microsoft.CostManagement/query/read smallest listed role: Cost Management Reader
Detailed invoiced costs cannot be shown.

Directory names

PurposeAccessIdentityDefault setupGrantWithout it
Resolves Azure principal IDs to names through Microsoft Graph.ReadConnected cloud accountExtra step
Microsoft Graph application permission
Show 1 exact permissions
Microsoft Graph Directory.Read.All smallest listed role: Microsoft Graph application permission
Scans show principal IDs instead of names.

Kubernetes visibility

PurposeAccessIdentityDefault setupGrantWithout it
Lists clusters and workload resources.ReadConnected cloud accountIncluded
Reader
Show 1 exact permissions
Microsoft.ContainerService/managedClusters/read smallest listed role: Reader
Cluster resources are missing from visibility views.

Costs and scans

PurposeAccessIdentityDefault setupGrantWithout it
Reads resources and usage for scheduled scans and cost views.ReadConnected cloud accountIncluded
Reader
Show 30 exact permissions
Microsoft.ApiManagement/service/read smallest listed role: Reader
Microsoft.App/containerApps/read smallest listed role: Reader
Microsoft.Authorization/roleAssignments/read smallest listed role: Reader
Microsoft.Cache/redis/read smallest listed role: Reader
Microsoft.CognitiveServices/accounts/read smallest listed role: Reader
Microsoft.Compute/disks/read smallest listed role: Reader
Microsoft.Compute/virtualMachineScaleSets/read smallest listed role: Reader
Microsoft.Compute/virtualMachines/read smallest listed role: Reader
Microsoft.ContainerRegistry/registries/read smallest listed role: Reader
Microsoft.DBforMySQL/flexibleServers/read smallest listed role: Reader
Microsoft.DBforPostgreSQL/flexibleServers/read smallest listed role: Reader
Microsoft.DocumentDB/databaseAccounts/read smallest listed role: Reader
Microsoft.EventHub/namespaces/read smallest listed role: Reader
Microsoft.Insights/metrics/read smallest listed role: Reader
Microsoft.KeyVault/vaults/read smallest listed role: Reader
Microsoft.Network/applicationGateways/read smallest listed role: Reader
Microsoft.Network/azureFirewalls/read smallest listed role: Reader
Microsoft.Network/bastionHosts/read smallest listed role: Reader
Microsoft.Network/loadBalancers/read smallest listed role: Reader
Microsoft.Network/natGateways/read smallest listed role: Reader
Microsoft.Network/networkSecurityGroups/read smallest listed role: Reader
Microsoft.Network/publicIPAddresses/read smallest listed role: Reader
Microsoft.Network/virtualNetworkGateways/read smallest listed role: Reader
Microsoft.OperationalInsights/workspaces/read smallest listed role: Reader
Microsoft.RecoveryServices/vaults/read smallest listed role: Reader
Microsoft.Resources/subscriptions/resources/read smallest listed role: Reader
Microsoft.ServiceBus/namespaces/read smallest listed role: Reader
Microsoft.Sql/servers/read smallest listed role: Reader
Microsoft.Storage/storageAccounts/read smallest listed role: Reader
Microsoft.Web/serverfarms/read smallest listed role: Reader
Those resources or costs can be missing from scans.

AutoStopping

PurposeAccessIdentityDefault setupGrantWithout it
Stops and starts selected idle compute resources.WriteConnected cloud accountExtra step
Virtual Machine Contributor
Show 2 exact permissions
Microsoft.Compute/virtualMachines/deallocate/action smallest listed role: Virtual Machine Contributor
Microsoft.Compute/virtualMachines/start/action smallest listed role: Virtual Machine Contributor
Automatic stopping and restart fail.

Autopilot fixes

PurposeAccessIdentityDefault setupGrantWithout it
Applies approved changes to cloud resources.WriteConnected cloud accountExtra step
Custom Azure role
Show 3 exact permissions
Microsoft.DBforMySQL/flexibleServers/write smallest listed role: Custom Azure role
Microsoft.DBforPostgreSQL/flexibleServers/write smallest listed role: Custom Azure role
Microsoft.Network/networkSecurityGroups/securityRules/write smallest listed role: Custom Azure role
Approved fixes cannot be applied.

Beam team access

PurposeAccessIdentityDefault setupGrantWithout it
Creates and revokes short lived human access grants.WriteBeam identityExtra step
Microsoft Graph application permission
User Access Administrator
Reader
Show 4 exact permissions
Application.ReadWrite.OwnedBy smallest listed role: Microsoft Graph application permission
Microsoft.Authorization/roleAssignments/delete smallest listed role: User Access Administrator
Microsoft.Authorization/roleAssignments/write smallest listed role: User Access Administrator
Microsoft.Authorization/roleDefinitions/read smallest listed role: Reader
Beam cannot mint or revoke those grants.

CI/CD and deploy

PurposeAccessIdentityDefault setupGrantWithout it
Runs deployment and infrastructure operations through the CI runner.WriteCI runnerExtra step
Contributor
Deployments and infrastructure jobs fail.

GitOps: install Argo CD

PurposeAccessIdentityDefault setupGrantWithout it
Installs Argo CD into a cluster so it can deploy your apps from Git.WriteDeploy identityExtra step
Azure Kubernetes Service RBAC Cluster Admin
Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster.

Permissions still being resolved

61 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.

Show call sites
  • lib/autopilot/cloud-exec.ts:409: approvedFixes. The inventory could not establish the exact provider action for this call.
  • lib/delivery/generate-jenkinsfile.ts:1173: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1181: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1187: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1203: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1212: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1740: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1772: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1983: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1996: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:2045: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:213: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:216: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:229: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:239: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:498: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:662: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:663: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:713: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:714: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:786: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:956: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:1800: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:1803: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:1816: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:1824: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3081: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3142: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3285: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3383: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3486: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3692: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3693: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3697: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3698: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3755: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4511: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4514: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5126: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5606: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5628: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5650: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5967: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6014: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6753: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6830: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6831: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6836: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6837: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6846: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6894: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7452: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7506: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7507: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7512: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7513: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7522: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8272: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8347: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8869: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.

DigitalOcean

Default connection grants: Read Only token

A Read Only token covers scans and history. AutoStopping, approved fixes and Beam changes require a Full Access token for the identity that performs them.

Cloud History

PurposeAccessIdentityDefault setupGrantWithout it
Reads provider activity so you can see what changed.ReadConnected cloud accountIncluded
Read Only token
Show 1 exact permissions
read:action smallest listed role: Read Only token
Cloud events and change history are unavailable.

Costs and scans

PurposeAccessIdentityDefault setupGrantWithout it
Reads resources and usage for scheduled scans and cost views.ReadConnected cloud accountIncluded
Read Only token
Show 1 exact permissions
read smallest listed role: Read Only token
Those resources or costs can be missing from scans.

AutoStopping

PurposeAccessIdentityDefault setupGrantWithout it
Stops and starts selected idle compute resources.WriteConnected cloud accountExtra step
Full Access token
Show 1 exact permissions
write smallest listed role: Full Access token
Automatic stopping and restart fail.

Autopilot fixes

PurposeAccessIdentityDefault setupGrantWithout it
Applies approved changes to cloud resources.WriteConnected cloud accountExtra step
Full Access token
Approved fixes cannot be applied.

Beam team access

PurposeAccessIdentityDefault setupGrantWithout it
Creates and revokes short lived human access grants.WriteBeam identityExtra step
Full Access token
Beam cannot mint or revoke those grants.

CI/CD and deploy

PurposeAccessIdentityDefault setupGrantWithout it
Runs deployment and infrastructure operations through the CI runner.WriteCI runnerExtra step
Full Access token
Deployments and infrastructure jobs fail.

GitOps: install Argo CD

PurposeAccessIdentityDefault setupGrantWithout it
Installs Argo CD into a cluster so it can deploy your apps from Git.WriteDeploy identityExtra step
Full Access API token
Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster.

Permissions still being resolved

45 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.

Show call sites
  • lib/autopilot/cloud-exec.ts:409: approvedFixes. The inventory could not establish the exact provider action for this call.
  • app/api/beam/do-api/[grantId]/[...path]/route.ts:218: access. The token access level is known, but the endpoint specific scope is not established.
  • app/api/beam/do-api/[grantId]/[...path]/route.ts:218: access. The token access level is known, but the endpoint specific scope is not established.
  • lib/delivery/generate-jenkinsfile.ts:1271: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1742: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1774: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:973: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:974: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3102: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3163: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3495: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3501: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3822: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5137: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5975: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5983: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6036: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:7775: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:8355: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/autostopping/cloud-actions.ts:469: autoStopping. The token access level is known, but the endpoint specific scope is not established.
  • lib/autostopping/cloud-actions.ts:684: autoStopping. The token access level is known, but the endpoint specific scope is not established.
  • lib/waste/real-cloud-cleanup.ts:31: oneClickCleanup. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2216: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2217: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2218: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2219: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2220: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2221: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2226: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2227: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/digitalocean.ts:2228: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/digitalocean.ts:2229: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2230: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2231: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2236: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2237: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2416: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2978: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2979: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2980: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:2983: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:347: scheduledScans. The inventory could not establish the exact provider action for this call.
  • lib/scanner/digitalocean.ts:453: scheduledScans. The token access level is known, but the endpoint specific scope is not established.
  • lib/scanner/digitalocean.ts:466: scheduledScans. The inventory could not establish the exact provider action for this call.

Kubernetes and OpenShift

Default connection grants: none. Configure cluster access separately.

Kubernetes visibility

PurposeAccessIdentityDefault setupGrantWithout it
Lists clusters and workload resources.ReadConnectorExtra step
Kubernetes RBAC rule
Show 35 exact permissions
list buildconfigs smallest listed role: Kubernetes RBAC rule
list builds smallest listed role: Kubernetes RBAC rule
list certificates smallest listed role: Kubernetes RBAC rule
list clusterrolebindings smallest listed role: Kubernetes RBAC rule
list clusterroles smallest listed role: Kubernetes RBAC rule
list clusterserviceversions smallest listed role: Kubernetes RBAC rule
list configmaps smallest listed role: Kubernetes RBAC rule
list cronjobs smallest listed role: Kubernetes RBAC rule
list daemonsets smallest listed role: Kubernetes RBAC rule
list deploymentconfigs smallest listed role: Kubernetes RBAC rule
list deployments smallest listed role: Kubernetes RBAC rule
list endpoints smallest listed role: Kubernetes RBAC rule
list events smallest listed role: Kubernetes RBAC rule
list horizontalpodautoscalers smallest listed role: Kubernetes RBAC rule
list imagestreams smallest listed role: Kubernetes RBAC rule
list ingressclasses smallest listed role: Kubernetes RBAC rule
list ingresses smallest listed role: Kubernetes RBAC rule
list jobs smallest listed role: Kubernetes RBAC rule
list limitranges smallest listed role: Kubernetes RBAC rule
list namespaces smallest listed role: Kubernetes RBAC rule
list networkpolicies smallest listed role: Kubernetes RBAC rule
list nodes smallest listed role: Kubernetes RBAC rule
list persistentvolumeclaims smallest listed role: Kubernetes RBAC rule
list persistentvolumes smallest listed role: Kubernetes RBAC rule
list poddisruptionbudgets smallest listed role: Kubernetes RBAC rule
list pods smallest listed role: Kubernetes RBAC rule
list replicasets smallest listed role: Kubernetes RBAC rule
list resourcequotas smallest listed role: Kubernetes RBAC rule
list rolebindings smallest listed role: Kubernetes RBAC rule
list roles smallest listed role: Kubernetes RBAC rule
list routes smallest listed role: Kubernetes RBAC rule
list secrets smallest listed role: Kubernetes RBAC rule
list services smallest listed role: Kubernetes RBAC rule
list statefulsets smallest listed role: Kubernetes RBAC rule
list storageclasses smallest listed role: Kubernetes RBAC rule
Cluster resources are missing from visibility views.

Beam team access

PurposeAccessIdentityDefault setupGrantWithout it
Creates and revokes short lived human access grants.WriteBeam identityExtra step
Kubernetes RBAC rule
Show 10 exact permissions
create clusterrolebindings smallest listed role: Kubernetes RBAC rule
create namespaces smallest listed role: Kubernetes RBAC rule
create rolebindings smallest listed role: Kubernetes RBAC rule
create roles smallest listed role: Kubernetes RBAC rule
create serviceaccounts smallest listed role: Kubernetes RBAC rule
create serviceaccounts/token smallest listed role: Kubernetes RBAC rule
delete clusterrolebindings smallest listed role: Kubernetes RBAC rule
delete rolebindings smallest listed role: Kubernetes RBAC rule
delete roles smallest listed role: Kubernetes RBAC rule
delete serviceaccounts smallest listed role: Kubernetes RBAC rule
Beam cannot mint or revoke those grants.

CI/CD and deploy

PurposeAccessIdentityDefault setupGrantWithout it
Runs deployment and infrastructure operations through the CI runner.WriteCI runnerExtra step
Kubernetes RBAC rule
Deployments and infrastructure jobs fail.

Permissions still being resolved

51 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.

Show call sites
  • lib/delivery/generate-jenkinsfile.ts:1023: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1039: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1045: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:1053: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:917: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:934: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:938: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:945: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:985: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-jenkinsfile.ts:998: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3449: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3462: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3463: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3467: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3485: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3494: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3522: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3524: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3527: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3552: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:3553: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4460: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:4461: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5877: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5882: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5887: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5901: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5920: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5926: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5933: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5948: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5949: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5954: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5966: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5974: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:5980: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6276: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6277: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6318: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6322: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6324: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6327: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6352: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6353: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6396: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/delivery/generate-terraform-workflow.ts:6407: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
  • lib/beam/openshift-doctor-apply.ts:309: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.
  • lib/beam/openshift-doctor-apply.ts:362: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.
  • lib/beam/openshift-doctor-apply.ts:173: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.
  • lib/beam/openshift-doctor-apply.ts:223: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.
  • lib/beam/openshift-doctor-apply.ts:415: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.

For setup steps, return to Getting started.