Organization · Web and Desktop · Team

Team and permissions

On Team, everyone signs in with their own GitHub and only sees the clients granted to them. Nobody needs to get a kubeconfig over chat. Kubepier permissions add to the RBAC of each cluster’s credential. The role applies on the web and, from version 2.7.0, on desktop.

Where
Web and Desktop (2.7.0)
Plans
Team
Role
Only admins manage the team

Roles

CanAdminMember
See clients and clustersAllOnly granted ones
Logs: recent linesYesYes, on granted ones
Live logs (paid plan)YesYes, on granted ones
Peek messages, MongoDB panel, Redis browser (paid plan)YesYes, on granted ones
Queue dashboard rates and alerts, AI diagnosis and the AI analyses screen (paid plan)YesYes, on granted ones
Set up the organization’s AI and queue backlog thresholds (paid plan)YesNo
Add clients, clusters, cloud accounts and service accessYesNo
Edit, scale, restart, delete, pod and node shell and bastion (paid plan)YesNo
Purge queues, edit and delete Redis keys (paid plan)YesNo
Audit log (paid plan)The whole organization, with a user filter, and CSV exportTheir own entries, on granted clients, and CSV export
Team, invites and subscriptionYesNo

Anything not granted to a member answers as if it did not exist.

On desktop, from 2.7.0, the same rule applies: the role comes with the account licence, members are read-only and admins do everything the plan allows, typing the name to delete, force, finalize, drain, open a node shell and uninstall a Helm release. Up to 2.6.0, the desktop app does not check the role. Per-client access only applies on the web: on desktop, each person sees the clients saved on their own machine.

On Free, the audit log is a preview: each person sees their own entries from the last 7 days, without CSV export.

Kubepier roles and read-only Kubernetes RBAC

The admin and member roles apply inside Kubepier. In the cluster, what counts is the RBAC of the saved credential: if it is a read-only ServiceAccount (the view ClusterRole), not even an admin can change the cluster from the web, even on Pro. For a team that only looks, pair the member role with a read-only credential.

Invites

  • Invite by GitHub username or generate a link.
  • Pick the role and the granted clients before sending.
  • The invite is valid for 7 days.
  • Whoever leaves the team loses web access right away. On desktop, they keep the paid features until the licence is checked again, within 6 hours.

What is not accepted

  • A member managing the team or changing their own role.
  • A member seeing in the audit log what other people did.
  • Granting a member a client from another organization.