tr33
09/07/2023, 11:28 AMvroldanbet
09/07/2023, 3:52 PMproject and spanner_instance. right now there is a granted at the project level that means that they will have permission on everything below that project level. If you want to constraint that to a specific type, then you can add another relation to definition project like, say, relation spanner_instance_manager: role_binding , and add it to only the permissions that relate to the definition spanner_instance.vroldanbet
09/07/2023, 3:53 PMvroldanbet
09/08/2023, 2:03 PMtr33
09/08/2023, 7:46 PMvroldanbet
09/08/2023, 9:12 PMtr33
09/11/2023, 8:36 AMvroldanbet
09/11/2023, 11:30 PMtr33
09/20/2023, 12:52 PMdocument:x#can_read@user:admin (which should always be true for any document id)vroldanbet
09/20/2023, 1:31 PMtr33
09/20/2023, 3:34 PMtr33
09/20/2023, 3:34 PMtr33
09/20/2023, 3:35 PMtr33
09/20/2023, 3:38 PM