Reference
Permissions reference
See the cloud roles and permissions each Zaysa feature needs.
About 8 minutes
To see what your connection has, use Check permissions.
The default connection setup grants read access for scans, costs and supported history views. It uses the roles listed below for each cloud. Billing exports in another project or storage account, team access, deploy jobs and changes to resources can need extra grants. Write features are always opt in and are never part of the default connection setup.
Each capability lists the identity that makes the call. Grant its roles to that identity at the scope where Zaysa reads or changes resources. If an action depends on a CLI command, model choice or API endpoint at runtime, the exact permission is still being established and the feature is marked as needing separate setup.
AWS
Default connection grants: ReadOnlyAccess
Cloud History
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads provider activity so you can see what changed. | Read | Connected cloud account | Included | ReadOnlyAccessShow 1 exact permissionscloudtrail:LookupEvents smallest listed role: ReadOnlyAccess | Cloud events and change history are unavailable. |
Billing export
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads detailed billing data and export tables. | Read | Connected cloud account | Included | ReadOnlyAccessShow 3 exact permissionsce:GetCostAndUsageWithResources smallest listed role: ReadOnlyAccesss3:GetObject smallest listed role: ReadOnlyAccesss3:ListBucket smallest listed role: ReadOnlyAccess | Detailed invoiced costs cannot be shown. |
Resource Explorer
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Lists AWS Resource Explorer resources during discovery. | Read | Connected cloud account | Extra step | Custom IAM allowShow 1 exact permissionsresource-explorer-2:ListResources smallest listed role: Custom IAM allow | Resource Explorer results are unavailable. |
Cloud account setup
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Creates the optional AWS Resource Explorer index. | Write | Connected cloud account | Extra step | Custom IAM allowShow 1 exact permissionsresource-explorer-2:CreateIndex smallest listed role: Custom IAM allow | The optional Resource Explorer index is not created. |
Kubernetes visibility
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Lists clusters and workload resources. | Read | Connected cloud account | Included | ReadOnlyAccessShow 4 exact permissionseks:DescribeCluster smallest listed role: ReadOnlyAccesseks:DescribeNodegroup smallest listed role: ReadOnlyAccesseks:ListClusters smallest listed role: ReadOnlyAccesseks:ListNodegroups smallest listed role: ReadOnlyAccess | Cluster resources are missing from visibility views. |
Costs and scans
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads resources and usage for scheduled scans and cost views. | Read | Connected cloud account | Included | ReadOnlyAccessShow 132 exact permissionsacm:ListCertificates smallest listed role: ReadOnlyAccessapigateway:GET smallest listed role: ReadOnlyAccessathena:GetWorkGroup smallest listed role: ReadOnlyAccessathena:ListWorkGroups smallest listed role: ReadOnlyAccessautoscaling:DescribeAutoScalingGroups smallest listed role: ReadOnlyAccessbackup:ListBackupVaults smallest listed role: ReadOnlyAccessbatch:DescribeComputeEnvironments smallest listed role: ReadOnlyAccessbatch:DescribeJobQueues smallest listed role: ReadOnlyAccessce:GetCostAndUsage smallest listed role: ReadOnlyAccesscloudformation:DescribeStacks smallest listed role: ReadOnlyAccesscloudfront:ListDistributions smallest listed role: ReadOnlyAccesscloudtrail:DescribeTrails smallest listed role: ReadOnlyAccesscloudtrail:GetTrailStatus smallest listed role: ReadOnlyAccesscloudwatch:DescribeAlarms smallest listed role: ReadOnlyAccesscloudwatch:GetMetricStatistics smallest listed role: ReadOnlyAccesscodebuild:BatchGetProjects smallest listed role: ReadOnlyAccesscodebuild:ListProjects smallest listed role: ReadOnlyAccessdms:DescribeEndpoints smallest listed role: ReadOnlyAccessdms:DescribeReplicationInstances smallest listed role: ReadOnlyAccessdynamodb:DescribeTable smallest listed role: ReadOnlyAccessdynamodb:ListTables smallest listed role: ReadOnlyAccessec2:DescribeAddresses smallest listed role: ReadOnlyAccessec2:DescribeFleets smallest listed role: ReadOnlyAccessec2:DescribeImages smallest listed role: ReadOnlyAccessec2:DescribeInstances smallest listed role: ReadOnlyAccessec2:DescribeInternetGateways smallest listed role: ReadOnlyAccessec2:DescribeManagedPrefixLists smallest listed role: ReadOnlyAccessec2:DescribeNatGateways smallest listed role: ReadOnlyAccessec2:DescribeNetworkAcls smallest listed role: ReadOnlyAccessec2:DescribeNetworkInterfaces smallest listed role: ReadOnlyAccessec2:DescribeRegions smallest listed role: ReadOnlyAccessec2:DescribeRouteTables smallest listed role: ReadOnlyAccessec2:DescribeSecurityGroupRules smallest listed role: ReadOnlyAccessec2:DescribeSecurityGroups smallest listed role: ReadOnlyAccessec2:DescribeSnapshots smallest listed role: ReadOnlyAccessec2:DescribeSubnets smallest listed role: ReadOnlyAccessec2:DescribeTransitGatewayAttachments smallest listed role: ReadOnlyAccessec2:DescribeTransitGateways smallest listed role: ReadOnlyAccessec2:DescribeVolumes smallest listed role: ReadOnlyAccessec2:DescribeVpcEndpoints smallest listed role: ReadOnlyAccessec2:DescribeVpcPeeringConnections smallest listed role: ReadOnlyAccessec2:DescribeVpcs smallest listed role: ReadOnlyAccessec2:DescribeVpnConnections smallest listed role: ReadOnlyAccessec2:DescribeVpnGateways smallest listed role: ReadOnlyAccessec2:GetManagedPrefixListEntries smallest listed role: ReadOnlyAccessecr:DescribeRepositories smallest listed role: ReadOnlyAccessecr:ListImages smallest listed role: ReadOnlyAccessecs:DescribeClusters smallest listed role: ReadOnlyAccessecs:DescribeServices smallest listed role: ReadOnlyAccessecs:DescribeTaskDefinition smallest listed role: ReadOnlyAccessecs:DescribeTasks smallest listed role: ReadOnlyAccessecs:ListClusters smallest listed role: ReadOnlyAccessecs:ListServices smallest listed role: ReadOnlyAccessecs:ListTasks smallest listed role: ReadOnlyAccesseks:DescribeFargateProfile smallest listed role: ReadOnlyAccesseks:ListFargateProfiles smallest listed role: ReadOnlyAccesselasticache:DescribeCacheClusters smallest listed role: ReadOnlyAccesselasticache:DescribeCacheSubnetGroups smallest listed role: ReadOnlyAccesselasticache:DescribeReplicationGroups smallest listed role: ReadOnlyAccesselasticache:DescribeServerlessCaches smallest listed role: ReadOnlyAccesselasticbeanstalk:DescribeApplications smallest listed role: ReadOnlyAccesselasticbeanstalk:DescribeEnvironments smallest listed role: ReadOnlyAccesselasticfilesystem:DescribeFileSystems smallest listed role: ReadOnlyAccesselasticfilesystem:DescribeMountTargetSecurityGroups smallest listed role: ReadOnlyAccesselasticfilesystem:DescribeMountTargets smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeInstanceHealth smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeListeners smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeLoadBalancers smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeRules smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeTags smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeTargetGroups smallest listed role: ReadOnlyAccesselasticloadbalancing:DescribeTargetHealth smallest listed role: ReadOnlyAccesses:DescribeDomain smallest listed role: ReadOnlyAccesses:DescribeDomains smallest listed role: ReadOnlyAccesses:ListDomainNames smallest listed role: ReadOnlyAccessevents:ListEventBuses smallest listed role: ReadOnlyAccessevents:ListRules smallest listed role: ReadOnlyAccessevents:ListTargetsByRule smallest listed role: ReadOnlyAccessfreetier:GetFreeTierUsage smallest listed role: ReadOnlyAccessglue:GetDatabases smallest listed role: ReadOnlyAccessglue:GetTables smallest listed role: ReadOnlyAccessiam:GenerateCredentialReport smallest listed role: ReadOnlyAccessiam:GetAccountAuthorizationDetails smallest listed role: ReadOnlyAccessiam:GetAccountPasswordPolicy smallest listed role: ReadOnlyAccessiam:GetAccountSummary smallest listed role: ReadOnlyAccessiam:GetCredentialReport smallest listed role: ReadOnlyAccessiam:ListAccessKeys smallest listed role: ReadOnlyAccessiam:ListAttachedUserPolicies smallest listed role: ReadOnlyAccessiam:ListMFADevices smallest listed role: ReadOnlyAccessiam:ListUsers smallest listed role: ReadOnlyAccesskafka:ListClustersV2 smallest listed role: ReadOnlyAccesskinesis:DescribeStreamSummary smallest listed role: ReadOnlyAccesskinesis:ListStreams smallest listed role: ReadOnlyAccesskms:DescribeKey smallest listed role: ReadOnlyAccesskms:ListKeys smallest listed role: ReadOnlyAccesslambda:ListEventSourceMappings smallest listed role: ReadOnlyAccesslambda:ListFunctions smallest listed role: ReadOnlyAccesslogs:DescribeLogGroups smallest listed role: ReadOnlyAccessmemorydb:DescribeClusters smallest listed role: ReadOnlyAccessmemorydb:DescribeSubnetGroups smallest listed role: ReadOnlyAccesspricing:GetProducts smallest listed role: ReadOnlyAccessrds:DescribeDBClusters smallest listed role: ReadOnlyAccessrds:DescribeDBInstances smallest listed role: ReadOnlyAccessrds:DescribeDBSnapshots smallest listed role: ReadOnlyAccessrds:DescribeDBSubnetGroups smallest listed role: ReadOnlyAccessredshift-serverless:ListNamespaces smallest listed role: ReadOnlyAccessredshift-serverless:ListWorkgroups smallest listed role: ReadOnlyAccessredshift:DescribeClusterSubnetGroups smallest listed role: ReadOnlyAccessredshift:DescribeClusters smallest listed role: ReadOnlyAccessresource-explorer-2:ListIndexes smallest listed role: ReadOnlyAccessresource-explorer-2:Search smallest listed role: ReadOnlyAccessroute53:GetHostedZone smallest listed role: ReadOnlyAccessroute53:ListHostedZones smallest listed role: ReadOnlyAccessroute53:ListResourceRecordSets smallest listed role: ReadOnlyAccesss3:GetBucketAcl smallest listed role: ReadOnlyAccesss3:GetBucketLifecycleConfiguration smallest listed role: ReadOnlyAccesss3:GetBucketLocation smallest listed role: ReadOnlyAccesss3:GetBucketPolicyStatus smallest listed role: ReadOnlyAccesss3:GetPublicAccessBlock smallest listed role: ReadOnlyAccesss3:ListBuckets smallest listed role: ReadOnlyAccesssagemaker:ListEndpoints smallest listed role: ReadOnlyAccesssagemaker:ListNotebookInstances smallest listed role: ReadOnlyAccesssecretsmanager:ListSecrets smallest listed role: ReadOnlyAccesssns:GetTopicAttributes smallest listed role: ReadOnlyAccesssns:ListSubscriptions smallest listed role: ReadOnlyAccesssns:ListTopics smallest listed role: ReadOnlyAccesssqs:GetQueueAttributes smallest listed role: ReadOnlyAccesssqs:ListQueues smallest listed role: ReadOnlyAccessstates:DescribeStateMachine smallest listed role: ReadOnlyAccessstates:ListStateMachines smallest listed role: ReadOnlyAccesstag:GetResources smallest listed role: ReadOnlyAccessworkspaces:DescribeWorkspaces smallest listed role: ReadOnlyAccess | Those resources or costs can be missing from scans. |
AutoStopping
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Stops and starts selected idle compute resources. | Write | Connected cloud account | Extra step | Custom IAM allowShow 5 exact permissionsautoscaling:CreateOrUpdateTags smallest listed role: Custom IAM allowautoscaling:SetDesiredCapacity smallest listed role: Custom IAM allowautoscaling:UpdateAutoScalingGroup smallest listed role: Custom IAM allowec2:StartInstances smallest listed role: Custom IAM allowec2:StopInstances smallest listed role: Custom IAM allow | Automatic stopping and restart fail. |
Autopilot fixes
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Applies approved changes to cloud resources. | Write | Connected cloud account | Extra step | Custom IAM allowShow 3 exact permissionsec2:RevokeSecurityGroupIngress smallest listed role: Custom IAM allowrds:ModifyDBInstance smallest listed role: Custom IAM allows3:PutPublicAccessBlock smallest listed role: Custom IAM allow | Approved fixes cannot be applied. |
CI/CD and deploy
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Runs deployment and infrastructure operations through the CI runner. | Write | CI runner | Extra step | Custom IAM allowPowerUserAccessShow 7 exact permissionsdynamodb:CreateTable smallest listed role: Custom IAM allowdynamodb:DeleteItem smallest listed role: Custom IAM allowdynamodb:PutItem smallest listed role: Custom IAM allows3:CreateBucket smallest listed role: Custom IAM allows3:DeleteObject smallest listed role: Custom IAM allows3:PutBucketVersioning smallest listed role: Custom IAM allows3:PutObject smallest listed role: Custom IAM allow | Deployments and infrastructure jobs fail. |
Beam team access
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Creates and revokes short lived human access grants. | Write | Beam identity | Extra step | Custom IAM allowReadOnlyAccessShow 12 exact permissionselasticache:CreateUser smallest listed role: Custom IAM allowelasticache:DeleteUser smallest listed role: Custom IAM allowelasticache:DescribeUserGroups smallest listed role: ReadOnlyAccesselasticache:ModifyUserGroup smallest listed role: Custom IAM allowiam:GetRole smallest listed role: ReadOnlyAccessiam:GetRolePolicy smallest listed role: ReadOnlyAccessiam:PutRolePolicy smallest listed role: Custom IAM allowmemorydb:CreateUser smallest listed role: Custom IAM allowmemorydb:DeleteUser smallest listed role: Custom IAM allowmemorydb:DescribeACLs smallest listed role: ReadOnlyAccessmemorydb:UpdateACL smallest listed role: Custom IAM allowsts:AssumeRole smallest listed role: Custom IAM allow | Beam cannot mint or revoke those grants. |
GitOps: install Argo CD
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Installs Argo CD into a cluster so it can deploy your apps from Git. | Write | Deploy identity | Extra step | EKS access entry: AmazonEKSClusterAdminPolicy (cluster scope) | Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster. |
Permissions still being resolved
76 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.
Show call sites
lib/autopilot/cloud-exec.ts:731: approvedFixes. The inventory could not establish the exact provider action for this call.lib/delivery/generate-jenkinsfile.ts:1097: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1098: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1100: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1101: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1110: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1119: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1120: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1131: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1132: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1144: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1150: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1151: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1164: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1739: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1771: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1860: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1865: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1868: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1891: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1896: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1898: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:2156: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:621: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:785: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:906: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:908: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:920: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:922: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:925: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:931: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3068: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3069: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3129: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3130: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3265: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3363: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3450: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3579: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3603: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3604: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3715: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3719: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3737: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4478: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4479: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4501: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5104: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5258: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5342: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5346: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5352: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5878: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5904: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5907: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5910: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5917: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6510: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6511: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6512: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6603: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6604: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6610: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6611: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6676: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7275: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7280: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7284: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7290: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7403: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8257: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8855: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/scanner/aws.ts:4140: scheduledScans. Identity check needs no IAM allow.lib/scanner/validate-live-credentials.ts:90: scheduledScans. Identity check needs no IAM allow.lib/cloud-map/aws/build.ts:79: cloudMap. Identity check needs no IAM allow.
Google Cloud
Default connection grants: roles/cloudasset.viewer, roles/compute.viewer, roles/monitoring.viewer, roles/recommender.viewer, roles/logging.viewer, roles/browser, roles/bigquery.jobUser, roles/bigquery.dataViewer, roles/container.viewer, roles/cloudsql.viewer, roles/storage.bucketViewer, roles/run.viewer, roles/cloudfunctions.viewer, roles/pubsub.viewer, roles/artifactregistry.reader, roles/redis.viewer, roles/file.viewer
roles/bigquery.jobUser lets Zaysa read the query jobs it creates for billing. The scanner list calls use service-specific viewer roles, including roles/storage.bucketViewer for bucket listing. Additional viewer roles remain for dynamic scanner calls.
Cloud History
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads provider activity so you can see what changed. | Read | Connected cloud account | Included | roles/logging.viewerShow 1 exact permissionslogging.logEntries.list smallest listed role: roles/logging.viewer | Cloud events and change history are unavailable. |
Billing export
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads detailed billing data and export tables. | Read | Connected cloud account | Included | roles/bigquery.jobUserroles/bigquery.dataViewerShow 3 exact permissionsbigquery.jobs.create smallest listed role: roles/bigquery.jobUserbigquery.jobs.get grant: roles/bigquery.jobUser (own jobs only)bigquery.tables.getData smallest listed role: roles/bigquery.dataViewer | Detailed invoiced costs cannot be shown. |
Kubernetes visibility
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Lists clusters and workload resources. | Read | Connected cloud account | Included | roles/container.viewerShow 1 exact permissionscontainer.clusters.list smallest listed role: roles/container.viewer | Cluster resources are missing from visibility views. |
Costs and scans
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads resources and usage for scheduled scans and cost views. | Read | Connected cloud account | Included | Show 13 rolesroles/artifactregistry.readerroles/cloudasset.viewerroles/cloudfunctions.viewerroles/cloudsql.viewerroles/file.viewerroles/pubsub.viewerroles/redis.viewerroles/run.viewerroles/storage.bucketViewerroles/compute.viewerroles/monitoring.viewerroles/recommender.viewerroles/browserShow 10 exact permissionsartifactregistry.repositories.list smallest listed role: roles/artifactregistry.readercloudasset.assets.searchAllIamPolicies smallest listed role: roles/cloudasset.viewercloudasset.assets.searchAllResources smallest listed role: roles/cloudfunctions.viewer; default uses roles/cloudasset.viewercloudfunctions.functions.list smallest listed role: roles/cloudfunctions.viewercloudsql.instances.list smallest listed role: roles/cloudsql.viewerfile.instances.list smallest listed role: roles/file.viewerpubsub.topics.list smallest listed role: roles/pubsub.viewerredis.instances.list smallest listed role: roles/redis.viewerrun.services.list smallest listed role: roles/run.viewerstorage.buckets.list smallest listed role: roles/storage.bucketViewer | Those resources or costs can be missing from scans. |
AutoStopping
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Stops and starts selected idle VM instances. | Write | Connected cloud account | Extra step | roles/compute.viewerCustom IAM roleShow 3 exact permissionscompute.instances.get smallest listed role: roles/compute.viewercompute.instances.start smallest listed role: Custom IAM rolecompute.instances.stop smallest listed role: Custom IAM role | Automatic stopping and restart fail. |
Autopilot fixes
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Applies approved changes to cloud resources. | Write | Connected cloud account | Extra step | roles/compute.viewerCustom IAM roleShow 2 exact permissionscompute.firewalls.get smallest listed role: roles/compute.viewercompute.firewalls.update smallest listed role: Custom IAM role | Approved fixes cannot be applied. |
Beam team access
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Creates and revokes short lived human access grants. | Write | Deploy identity | Extra step | roles/iam.serviceAccountAdminroles/iam.serviceAccountTokenCreatorroles/iam.securityReviewerroles/resourcemanager.projectIamAdminShow 7 exact permissionsiam.serviceAccounts.create smallest listed role: roles/iam.serviceAccountAdminiam.serviceAccounts.delete smallest listed role: roles/iam.serviceAccountAdminiam.serviceAccounts.disable smallest listed role: roles/iam.serviceAccountAdminiam.serviceAccounts.getAccessToken smallest listed role: roles/iam.serviceAccountTokenCreatoriam.serviceAccounts.getIamPolicy smallest listed role: roles/iam.securityRevieweriam.serviceAccounts.setIamPolicy smallest listed role: roles/iam.serviceAccountAdminresourcemanager.projects.setIamPolicy smallest listed role: roles/resourcemanager.projectIamAdmin | Beam cannot mint or revoke those grants. |
Autopilot insights
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads cloud signals for findings and database checks. | Read | Connected cloud account | Extra step | The exact grant depends on the operation. | Some findings or database signals are unavailable. |
CI/CD and deploy
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Runs deployment and infrastructure operations through the CI runner. | Write | CI runner | Extra step | Show 41 rolesroles/container.adminroles/run.adminroles/compute.adminroles/cloudfunctions.adminroles/artifactregistry.adminroles/storage.adminroles/cloudsql.adminroles/serviceusage.serviceUsageAdminroles/iam.serviceAccountAdminroles/iam.serviceAccountUserroles/iap.tunnelResourceAccessorroles/compute.osAdminLoginroles/pubsub.adminroles/bigquery.adminroles/secretmanager.adminroles/dns.adminroles/monitoring.adminroles/logging.adminroles/cloudkms.adminroles/cloudscheduler.adminroles/cloudtasks.adminroles/workflows.adminroles/spanner.adminroles/bigtable.adminroles/alloydb.adminroles/redis.adminroles/memorystore.adminroles/memcache.adminroles/file.editorroles/datastore.ownerroles/dataproc.adminroles/dataflow.adminroles/composer.adminroles/cloudbuild.builds.editorroles/aiplatform.adminroles/notebooks.adminroles/certificatemanager.editorroles/binaryauthorization.policyEditorroles/dataplex.adminroles/resourcemanager.tagAdminroles/iam.workloadIdentityPoolAdmin | Deployments and infrastructure jobs fail. |
GitOps: install Argo CD
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Installs Argo CD into a cluster so it can deploy your apps from Git. | Write | Deploy identity | Extra step | roles/container.admin | Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster. |
Cloud Map
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads resource configuration and the effective firewall of each VPC network to draw the Cloud Map. | Read | Connected cloud account | Included | roles/cloudasset.viewerroles/compute.viewerShow 3 exact permissionscloudasset.assets.listResource smallest listed role: roles/cloudasset.viewercompute.networks.getEffectiveFirewalls smallest listed role: roles/compute.viewercompute.networks.getRegionEffectiveFirewalls smallest listed role: roles/compute.viewer | The Cloud Map shows resources without configured lines, can-reach lines or internet exposure. |
Permissions still being resolved
68 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.
Show call sites
lib/cloud-accounts/verify-deploy-permissions.ts:142: Other cloud operation. The inventory could not establish the exact provider action for this call.lib/pricing/fetch-gcp.ts:73: Other cloud operation. The inventory could not establish the exact provider action for this call.lib/autopilot/cloud-exec.ts:409: approvedFixes. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cert-expiry.ts:631: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-link.ts:547: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals-families.ts:875: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals-families.ts:987: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals.ts:1403: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals.ts:1416: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals.ts:1443: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals.ts:1476: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals.ts:1511: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/db-cloud-signals.ts:1543: databases. The inventory could not establish the exact provider action for this call.lib/autopilot/ai-diagnose.ts:186: findings. The inventory could not establish the exact provider action for this call.lib/autopilot/cloud-fix.ts:306: findings. The inventory could not establish the exact provider action for this call.lib/autopilot/cloud-regions.ts:72: findings. The inventory could not establish the exact provider action for this call.lib/autopilot/cloud-repair.ts:97: findings. The inventory could not establish the exact provider action for this call.lib/autopilot/vm-cloud-state.ts:248: findings. The inventory could not establish the exact provider action for this call.lib/delivery/generate-jenkinsfile.ts:1220: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1230: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1236: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1253: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1264: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1363: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1982: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1995: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:681: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:683: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:698: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:725: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:75: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:951: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3475: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3640: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3644: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3779: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3801: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4489: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5116: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5492: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5512: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5534: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5957: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:627: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7115: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7120: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7130: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7556: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7595: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7599: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7602: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7608: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7693: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8862: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/pr-gates/pricing/gcp-live.ts:106: prCostGates. The inventory could not establish the exact provider action for this call.lib/pr-gates/pricing/gcp-live.ts:160: prCostGates. The inventory could not establish the exact provider action for this call.lib/ai/deploy/gcp-required-apis.ts:70: stacks. The inventory could not establish the exact provider action for this call.lib/deploy/unmanaged-scan.ts:958: stacks. The inventory could not establish the exact provider action for this call.lib/scanner/gcp-monitoring.ts:174: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp-monitoring.ts:62: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp-recommender.ts:55: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp-storage-softdelete.ts:66: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp-vm-pricing.ts:226: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp.ts:1939: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp.ts:1974: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/gcp.ts:422: scheduledScans. The inventory could not establish the exact provider action for this call.lib/kubernetes/pricing/sources/gcp.ts:149: kubernetes. The inventory could not establish the exact provider action for this call.
Azure
Default connection grants: Reader, Cost Management Reader
Microsoft Graph Directory.Read.All is an Entra API permission, not an Azure RBAC role. It is optional: without it, principal IDs appear instead of names. Reading billing export blobs needs Storage Blob Data Reader at the storage account.
Cloud History
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads provider activity so you can see what changed. | Read | Connected cloud account | Included | ReaderShow 1 exact permissionsMicrosoft.Insights/eventtypes/management/values/read smallest listed role: Reader | Cloud events and change history are unavailable. |
Billing export storage
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads an Azure billing export from blob storage. | Read | Connected cloud account | Extra step | Storage Blob Data ReaderShow 1 exact permissionsMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/read smallest listed role: Storage Blob Data Reader | Blob based billing exports cannot be imported. |
Billing export
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads detailed billing data and export tables. | Read | Connected cloud account | Included | Cost Management ReaderShow 1 exact permissionsMicrosoft.CostManagement/query/read smallest listed role: Cost Management Reader | Detailed invoiced costs cannot be shown. |
Directory names
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Resolves Azure principal IDs to names through Microsoft Graph. | Read | Connected cloud account | Extra step | Microsoft Graph application permissionShow 1 exact permissionsMicrosoft Graph Directory.Read.All smallest listed role: Microsoft Graph application permission | Scans show principal IDs instead of names. |
Kubernetes visibility
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Lists clusters and workload resources. | Read | Connected cloud account | Included | ReaderShow 1 exact permissionsMicrosoft.ContainerService/managedClusters/read smallest listed role: Reader | Cluster resources are missing from visibility views. |
Costs and scans
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads resources and usage for scheduled scans and cost views. | Read | Connected cloud account | Included | ReaderShow 30 exact permissionsMicrosoft.ApiManagement/service/read smallest listed role: ReaderMicrosoft.App/containerApps/read smallest listed role: ReaderMicrosoft.Authorization/roleAssignments/read smallest listed role: ReaderMicrosoft.Cache/redis/read smallest listed role: ReaderMicrosoft.CognitiveServices/accounts/read smallest listed role: ReaderMicrosoft.Compute/disks/read smallest listed role: ReaderMicrosoft.Compute/virtualMachineScaleSets/read smallest listed role: ReaderMicrosoft.Compute/virtualMachines/read smallest listed role: ReaderMicrosoft.ContainerRegistry/registries/read smallest listed role: ReaderMicrosoft.DBforMySQL/flexibleServers/read smallest listed role: ReaderMicrosoft.DBforPostgreSQL/flexibleServers/read smallest listed role: ReaderMicrosoft.DocumentDB/databaseAccounts/read smallest listed role: ReaderMicrosoft.EventHub/namespaces/read smallest listed role: ReaderMicrosoft.Insights/metrics/read smallest listed role: ReaderMicrosoft.KeyVault/vaults/read smallest listed role: ReaderMicrosoft.Network/applicationGateways/read smallest listed role: ReaderMicrosoft.Network/azureFirewalls/read smallest listed role: ReaderMicrosoft.Network/bastionHosts/read smallest listed role: ReaderMicrosoft.Network/loadBalancers/read smallest listed role: ReaderMicrosoft.Network/natGateways/read smallest listed role: ReaderMicrosoft.Network/networkSecurityGroups/read smallest listed role: ReaderMicrosoft.Network/publicIPAddresses/read smallest listed role: ReaderMicrosoft.Network/virtualNetworkGateways/read smallest listed role: ReaderMicrosoft.OperationalInsights/workspaces/read smallest listed role: ReaderMicrosoft.RecoveryServices/vaults/read smallest listed role: ReaderMicrosoft.Resources/subscriptions/resources/read smallest listed role: ReaderMicrosoft.ServiceBus/namespaces/read smallest listed role: ReaderMicrosoft.Sql/servers/read smallest listed role: ReaderMicrosoft.Storage/storageAccounts/read smallest listed role: ReaderMicrosoft.Web/serverfarms/read smallest listed role: Reader | Those resources or costs can be missing from scans. |
AutoStopping
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Stops and starts selected idle compute resources. | Write | Connected cloud account | Extra step | Virtual Machine ContributorShow 2 exact permissionsMicrosoft.Compute/virtualMachines/deallocate/action smallest listed role: Virtual Machine ContributorMicrosoft.Compute/virtualMachines/start/action smallest listed role: Virtual Machine Contributor | Automatic stopping and restart fail. |
Autopilot fixes
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Applies approved changes to cloud resources. | Write | Connected cloud account | Extra step | Custom Azure roleShow 3 exact permissionsMicrosoft.DBforMySQL/flexibleServers/write smallest listed role: Custom Azure roleMicrosoft.DBforPostgreSQL/flexibleServers/write smallest listed role: Custom Azure roleMicrosoft.Network/networkSecurityGroups/securityRules/write smallest listed role: Custom Azure role | Approved fixes cannot be applied. |
Beam team access
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Creates and revokes short lived human access grants. | Write | Beam identity | Extra step | Microsoft Graph application permissionUser Access AdministratorReaderShow 4 exact permissionsApplication.ReadWrite.OwnedBy smallest listed role: Microsoft Graph application permissionMicrosoft.Authorization/roleAssignments/delete smallest listed role: User Access AdministratorMicrosoft.Authorization/roleAssignments/write smallest listed role: User Access AdministratorMicrosoft.Authorization/roleDefinitions/read smallest listed role: Reader | Beam cannot mint or revoke those grants. |
CI/CD and deploy
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Runs deployment and infrastructure operations through the CI runner. | Write | CI runner | Extra step | Contributor | Deployments and infrastructure jobs fail. |
GitOps: install Argo CD
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Installs Argo CD into a cluster so it can deploy your apps from Git. | Write | Deploy identity | Extra step | Azure Kubernetes Service RBAC Cluster Admin | Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster. |
Permissions still being resolved
61 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.
Show call sites
lib/autopilot/cloud-exec.ts:409: approvedFixes. The inventory could not establish the exact provider action for this call.lib/delivery/generate-jenkinsfile.ts:1173: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1181: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1187: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1203: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1212: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1740: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1772: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1983: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1996: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:2045: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:213: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:216: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:229: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:239: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:498: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:662: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:663: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:713: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:714: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:786: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:956: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:1800: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:1803: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:1816: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:1824: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3081: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3142: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3285: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3383: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3486: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3692: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3693: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3697: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3698: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3755: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4511: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4514: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5126: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5606: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5628: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5650: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5967: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6014: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6753: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6830: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6831: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6836: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6837: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6846: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6894: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7452: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7506: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7507: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7512: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7513: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7522: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8272: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8347: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8869: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.
DigitalOcean
Default connection grants: Read Only token
A Read Only token covers scans and history. AutoStopping, approved fixes and Beam changes require a Full Access token for the identity that performs them.
Cloud History
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads provider activity so you can see what changed. | Read | Connected cloud account | Included | Read Only tokenShow 1 exact permissionsread:action smallest listed role: Read Only token | Cloud events and change history are unavailable. |
Costs and scans
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Reads resources and usage for scheduled scans and cost views. | Read | Connected cloud account | Included | Read Only tokenShow 1 exact permissionsread smallest listed role: Read Only token | Those resources or costs can be missing from scans. |
AutoStopping
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Stops and starts selected idle compute resources. | Write | Connected cloud account | Extra step | Full Access tokenShow 1 exact permissionswrite smallest listed role: Full Access token | Automatic stopping and restart fail. |
Autopilot fixes
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Applies approved changes to cloud resources. | Write | Connected cloud account | Extra step | Full Access token | Approved fixes cannot be applied. |
Beam team access
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Creates and revokes short lived human access grants. | Write | Beam identity | Extra step | Full Access token | Beam cannot mint or revoke those grants. |
CI/CD and deploy
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Runs deployment and infrastructure operations through the CI runner. | Write | CI runner | Extra step | Full Access token | Deployments and infrastructure jobs fail. |
GitOps: install Argo CD
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Installs Argo CD into a cluster so it can deploy your apps from Git. | Write | Deploy identity | Extra step | Full Access API token | Zaysa stops before installing Argo CD and shows the one command that grants it; nothing is changed in the cluster. |
Permissions still being resolved
45 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.
Show call sites
lib/autopilot/cloud-exec.ts:409: approvedFixes. The inventory could not establish the exact provider action for this call.app/api/beam/do-api/[grantId]/[...path]/route.ts:218: access. The token access level is known, but the endpoint specific scope is not established.app/api/beam/do-api/[grantId]/[...path]/route.ts:218: access. The token access level is known, but the endpoint specific scope is not established.lib/delivery/generate-jenkinsfile.ts:1271: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1742: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1774: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:973: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:974: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3102: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3163: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3495: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3501: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3822: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5137: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5975: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5983: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6036: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:7775: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:8355: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/drift/check.ts:298: liveInfra. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/autostopping/cloud-actions.ts:469: autoStopping. The token access level is known, but the endpoint specific scope is not established.lib/autostopping/cloud-actions.ts:684: autoStopping. The token access level is known, but the endpoint specific scope is not established.lib/waste/real-cloud-cleanup.ts:31: oneClickCleanup. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2216: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2217: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2218: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2219: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2220: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2221: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2226: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2227: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/digitalocean.ts:2228: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/digitalocean.ts:2229: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2230: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2231: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2236: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2237: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2416: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2978: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2979: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2980: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:2983: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:347: scheduledScans. The inventory could not establish the exact provider action for this call.lib/scanner/digitalocean.ts:453: scheduledScans. The token access level is known, but the endpoint specific scope is not established.lib/scanner/digitalocean.ts:466: scheduledScans. The inventory could not establish the exact provider action for this call.
Kubernetes and OpenShift
Default connection grants: none. Configure cluster access separately.
Kubernetes visibility
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Lists clusters and workload resources. | Read | Connector | Extra step | Kubernetes RBAC ruleShow 35 exact permissionslist buildconfigs smallest listed role: Kubernetes RBAC rulelist builds smallest listed role: Kubernetes RBAC rulelist certificates smallest listed role: Kubernetes RBAC rulelist clusterrolebindings smallest listed role: Kubernetes RBAC rulelist clusterroles smallest listed role: Kubernetes RBAC rulelist clusterserviceversions smallest listed role: Kubernetes RBAC rulelist configmaps smallest listed role: Kubernetes RBAC rulelist cronjobs smallest listed role: Kubernetes RBAC rulelist daemonsets smallest listed role: Kubernetes RBAC rulelist deploymentconfigs smallest listed role: Kubernetes RBAC rulelist deployments smallest listed role: Kubernetes RBAC rulelist endpoints smallest listed role: Kubernetes RBAC rulelist events smallest listed role: Kubernetes RBAC rulelist horizontalpodautoscalers smallest listed role: Kubernetes RBAC rulelist imagestreams smallest listed role: Kubernetes RBAC rulelist ingressclasses smallest listed role: Kubernetes RBAC rulelist ingresses smallest listed role: Kubernetes RBAC rulelist jobs smallest listed role: Kubernetes RBAC rulelist limitranges smallest listed role: Kubernetes RBAC rulelist namespaces smallest listed role: Kubernetes RBAC rulelist networkpolicies smallest listed role: Kubernetes RBAC rulelist nodes smallest listed role: Kubernetes RBAC rulelist persistentvolumeclaims smallest listed role: Kubernetes RBAC rulelist persistentvolumes smallest listed role: Kubernetes RBAC rulelist poddisruptionbudgets smallest listed role: Kubernetes RBAC rulelist pods smallest listed role: Kubernetes RBAC rulelist replicasets smallest listed role: Kubernetes RBAC rulelist resourcequotas smallest listed role: Kubernetes RBAC rulelist rolebindings smallest listed role: Kubernetes RBAC rulelist roles smallest listed role: Kubernetes RBAC rulelist routes smallest listed role: Kubernetes RBAC rulelist secrets smallest listed role: Kubernetes RBAC rulelist services smallest listed role: Kubernetes RBAC rulelist statefulsets smallest listed role: Kubernetes RBAC rulelist storageclasses smallest listed role: Kubernetes RBAC rule | Cluster resources are missing from visibility views. |
Beam team access
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Creates and revokes short lived human access grants. | Write | Beam identity | Extra step | Kubernetes RBAC ruleShow 10 exact permissionscreate clusterrolebindings smallest listed role: Kubernetes RBAC rulecreate namespaces smallest listed role: Kubernetes RBAC rulecreate rolebindings smallest listed role: Kubernetes RBAC rulecreate roles smallest listed role: Kubernetes RBAC rulecreate serviceaccounts smallest listed role: Kubernetes RBAC rulecreate serviceaccounts/token smallest listed role: Kubernetes RBAC ruledelete clusterrolebindings smallest listed role: Kubernetes RBAC ruledelete rolebindings smallest listed role: Kubernetes RBAC ruledelete roles smallest listed role: Kubernetes RBAC ruledelete serviceaccounts smallest listed role: Kubernetes RBAC rule | Beam cannot mint or revoke those grants. |
CI/CD and deploy
| Purpose | Access | Identity | Default setup | Grant | Without it |
|---|---|---|---|---|---|
| Runs deployment and infrastructure operations through the CI runner. | Write | CI runner | Extra step | Kubernetes RBAC rule | Deployments and infrastructure jobs fail. |
Permissions still being resolved
51 call sites have an action chosen at runtime or an endpoint scope that the inventory could not establish. These calls are outside the verified default grant.
Show call sites
lib/delivery/generate-jenkinsfile.ts:1023: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1039: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1045: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:1053: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:917: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:934: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:938: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:945: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:985: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-jenkinsfile.ts:998: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3449: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3462: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3463: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3467: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3485: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3494: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3522: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3524: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3527: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3552: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:3553: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4460: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:4461: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5877: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5882: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5887: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5901: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5920: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5926: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5933: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5948: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5949: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5954: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5966: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5974: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:5980: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6276: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6277: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6318: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6322: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6324: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6327: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6352: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6353: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6396: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/delivery/generate-terraform-workflow.ts:6407: cicd. The endpoint or CLI resource is selected at runtime; the exact action is not fixed.lib/beam/openshift-doctor-apply.ts:309: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.lib/beam/openshift-doctor-apply.ts:362: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.lib/beam/openshift-doctor-apply.ts:173: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.lib/beam/openshift-doctor-apply.ts:223: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.lib/beam/openshift-doctor-apply.ts:415: access. The OpenShift resource kind is selected by the requested path; its RBAC resource cannot be fixed here.
For setup steps, return to Getting started.