Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ agents.md export-ignore
.agents export-ignore
SKILLS.md export-ignore
CLAUDE.md export-ignore
.claude export-ignore

.asf.yaml export-ignore
.bash_completion export-ignore
Expand Down
13 changes: 13 additions & 0 deletions java-sdk/.gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,16 @@

# Binary files should be left untouched
*.jar binary

# Keep the Gradle wrapper jar and scripts out of source releases.
# See: https://issues.apache.org/jira/browse/LEGAL-570
# This intentionally does not exclude the entire gradle/wrapper directory so
# gradle-wrapper.properties is kept. This file carries the pinned Gradle version
# and distribution checksum for a verifier to use when regenerating the wrapper.
/gradlew export-ignore
/gradlew.bat export-ignore
/gradle/wrapper/gradle-wrapper.jar export-ignore

# ktlint reads .editorconfig for its formatting rules at build time, and the
# build task requires the lint to pass, so the source release must ship it.
/.editorconfig -export-ignore
20 changes: 20 additions & 0 deletions providers/edge3/docs/ui_plugin.rst
Original file line number Diff line number Diff line change
Expand Up @@ -64,5 +64,25 @@ To be able to use the UI plugin you need to be in role "Admin" or "Op" or have t
configure the remote workers (Technical key: AccessView.JOBS). With this permission you can also manage
the workers like adjusting queues, concurrency, set them to maintenance mode or shutdown the workers.

.. warning::

"can read on Jobs" (``AccessView.JOBS``) is the **management** permission for Edge workers, not a
read-only one. It is deliberately the single permission gating the whole plugin, and the worker
management endpoints under ``/edge_worker/ui/`` check only this permission -- the HTTP method is not
part of the check. "can read on Plugins" governs only whether the plugin appears in the UI
navigation; it is not required in order to call the endpoints.

A principal holding "can read on Jobs" can therefore shut down, delete, re-queue and retune Edge
workers by calling those endpoints directly, whether or not the plugin is visible to them.

This matters for the default ``Viewer`` role, which **includes "can read on Jobs"**. In a default
Flask AppBuilder setup a Viewer does not see the Edge plugin in the navigation (Viewer has no
"can read on Plugins"), but can still reach the worker management endpoints. If Viewers in your
deployment must not manage Edge workers, remove "can read on Jobs" from that role or give those
users a custom role without it.

Finer-grained separation of read and management permissions for Edge workers is not implemented;
it is listed under :doc:`architecture` as a known missing feature.

Note that maintenance mode can also be adjusted via CLI.
See :ref:`deployment:maintenance` for more details.
Loading