Skip to content
Proud to collaborate with Microsoft for Startups

kubernetes.rbac.can_i ​

Check whether the connection's identity can perform a verb on a resource (kubectl auth can-i equivalent)

Check whether the connection's identity can perform a verb on a resource (kubectl auth can-i equivalent).

Inputs:

  • connection_uuid: Cloud connection UUID (required)
  • verb: Action to check — get/list/create/update/patch/delete/watch/deletecollection (required)
  • resource: Resource type, e.g. "deployments", "pods" (required)
  • group: API group, e.g. "apps"; empty/None for core API (optional)
  • namespace: Namespace scope; omit for cluster-scoped check (optional)
  • name: Specific resource instance name (optional)

Outputs:

  • allowed: bool — True if the server authorises the action
  • reason: str|None — the authorizer's evaluation message (may be None)

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-kubernetes
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes——
verbstringYes——
resourcestringYes——
groupstringNo——
namespacestringNo——
namestringNo——
organization_uuiduuidNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo——
organization_uuiduuidNo——
verbstringNo——
resourcestringNo——
groupstringNo——
namespacestringNo——
namestringNo——
allowedbooleanYes——
reasonstringNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "kubernetes.rbac.can_i",
  "initial_data": {
    "connection_uuid": "value",
    "verb": "value",
    "resource": "value"
  }
}