github.com/argoproj/argo-cd/v2@v2.10.9/assets/builtin-policy.csv (about)

     1  # Built-in policy which defines two roles: role:readonly and role:admin,
     2  # and additionally assigns the admin user to the role:admin role.
     3  # There are two policy formats:
     4  # 1. Applications, logs, and exec (which belong to a project):
     5  # p, <user/group>, <resource>, <action>, <project>/<object>
     6  # 2. All other resources:
     7  # p, <user/group>, <resource>, <action>, <object>
     8  
     9  p, role:readonly, applications, get, */*, allow
    10  p, role:readonly, certificates, get, *, allow
    11  p, role:readonly, clusters, get, *, allow
    12  p, role:readonly, repositories, get, *, allow
    13  p, role:readonly, projects, get, *, allow
    14  p, role:readonly, accounts, get, *, allow
    15  p, role:readonly, gpgkeys, get, *, allow
    16  p, role:readonly, logs, get, */*, allow
    17  
    18  p, role:admin, applications, create, */*, allow
    19  p, role:admin, applications, update, */*, allow
    20  p, role:admin, applications, delete, */*, allow
    21  p, role:admin, applications, sync, */*, allow
    22  p, role:admin, applications, override, */*, allow
    23  p, role:admin, applications, action/*, */*, allow
    24  p, role:admin, applicationsets, get, */*, allow
    25  p, role:admin, applicationsets, create, */*, allow
    26  p, role:admin, applicationsets, update, */*, allow
    27  p, role:admin, applicationsets, delete, */*, allow
    28  p, role:admin, certificates, create, *, allow
    29  p, role:admin, certificates, update, *, allow
    30  p, role:admin, certificates, delete, *, allow
    31  p, role:admin, clusters, create, *, allow
    32  p, role:admin, clusters, update, *, allow
    33  p, role:admin, clusters, delete, *, allow
    34  p, role:admin, repositories, create, *, allow
    35  p, role:admin, repositories, update, *, allow
    36  p, role:admin, repositories, delete, *, allow
    37  p, role:admin, projects, create, *, allow
    38  p, role:admin, projects, update, *, allow
    39  p, role:admin, projects, delete, *, allow
    40  p, role:admin, accounts, update, *, allow
    41  p, role:admin, gpgkeys, create, *, allow
    42  p, role:admin, gpgkeys, delete, *, allow
    43  p, role:admin, exec, create, */*, allow
    44  
    45  g, role:admin, role:readonly
    46  g, admin, role:admin