dsieczko
11/23/2022, 5:43 PMyetitwo
11/23/2022, 5:53 PMyetitwo
11/23/2022, 5:53 PMvroldanbet
11/23/2022, 5:59 PMyetitwo
11/23/2022, 6:02 PMvroldanbet
11/23/2022, 6:03 PMjzelinskie
11/23/2022, 6:34 PMyetitwo
11/23/2022, 6:53 PMRobertM
11/24/2022, 2:26 AMJoey
11/24/2022, 2:27 AMRobertM
11/24/2022, 2:28 AMJoey
11/24/2022, 2:28 AMYansong
11/24/2022, 3:34 AMdefinition user {}
definition role {
relation project_manager: user
relation dev: user
relation admin: user
}
definition codebase {
relation member: role#dev | role#admin
permission view = member
}
definition schedule {
relation member: role#project_manager | role#admin
permission view = member
}
it looks weird...RobertM
11/24/2022, 3:44 AM- name: PG_USER
valueFrom:
secretKeyRef:
name: pguser-credentials-secret
key: user
- name: PG_PASSWORD
valueFrom:
secretKeyRef:
name: pguser-credentials-secret
key: password
- name: PG_HOST
valueFrom:
secretKeyRef:
name: pguser-credentials-secret
key: host
- name: "SPICEDB_DATASTORE_CONN_URI"
value: postgres://$(PG_USER):$(PG_PASSWORD)@$(PG_HOST):5432/spicedb
Yansong
11/24/2022, 3:54 AMJoey
11/24/2022, 4:24 AMpassthrough
to give the otherwise defined configJoey
11/24/2022, 4:24 AMJoey
11/24/2022, 4:25 AMYansong
11/24/2022, 4:28 AMYansong
11/24/2022, 4:29 AMJoey
11/24/2022, 4:33 AMJoey
11/24/2022, 4:33 AMrole
typeYansong
11/24/2022, 4:35 AMYansong
11/24/2022, 7:55 AMdefinition user {}
definition group {
/**
* member can include both users and *the set of members* of other specific groups.
*/
relation member: user | group#member
}
Yansong
11/24/2022, 7:56 AMrelation member: user | group#member
and relation member: user | group
? i am a little bit confused by the docvroldanbet
11/24/2022, 8:21 AMgroup#member
makes references to the member
relation in group
. So instead of pointing to the group (by using group
), you are pointing to the members of an specific group.Yansong
11/24/2022, 8:23 AMYansong
11/24/2022, 8:24 AMYansong
11/24/2022, 8:24 AMvroldanbet
11/24/2022, 8:35 AMgroup:1#member@user:1
- group:1#member@group:2#member