Commit

A workspace's runners are its owners' to see, through the API too; docs for the new sidebar and Settings

Listing a workspace's runners, groups and runner settings now needs the owner role, as changing them did. The workspaces guide describes the shorter main list and what moved into Settings.

syntaqxcommitted Parent1378eefBrowse files
5 files+24−150/5 viewed
+2−2
914914 Op::SetActionsVariable => "Add or change a variable's row, as for secrets.",
915915 Op::DeleteActionsVariable => "Remove a variable: one row by `id`, or every row of the key.",
916916 Op::ListRunners => {
917− "A workspace's self-hosted runners, or a repository's: its own and the workspace's that its runner group lets it use. Each has its `labels` (always `self-hosted`, its OS and its architecture), `status` (`online`, `busy` or `offline`), the `work` it is doing, its `version` and when it was last seen. A workspace's are seen by its members; a repository's need the Admin role on it."
917+ "A workspace's self-hosted runners, or a repository's: its own and the workspace's that its runner group lets it use. Each has its `labels` (always `self-hosted`, its OS and its architecture), `status` (`online`, `busy` or `offline`), the `work` it is doing, its `version` and when it was last seen. A workspace's are seen by its owners; a repository's need the Admin role on it."
918918 }
919919 Op::ListRunnerGroups => {
920− "A workspace's runner groups: which of its repositories may use the runners in each. The default group (every repository) is where runners go when no group is named. Members only."
920+ "A workspace's runner groups: which of its repositories may use the runners in each. The default group (every repository) is where runners go when no group is named. Owners only."
921921 }
922922 Op::GetRunnerSettings => {
923923 "Where a workspace's (or a repository's) g1t agent work runs, and whether pull requests from forks may use its self-hosted runners. `agents_on_self_hosted` sends agent runs, checks, reviews and the merge queue to runners with `agent_labels` instead of g1t's sandboxes. A repository's are its workspace's unless it has its own (`inherited`)."
+1−1
1818
1919 | Where | Page | Who manages it |
2020 | --- | --- | --- |
21−| A workspace | **Settings → Runners**, `g1t.sh/<workspace>/-/runners` | Owners. Members can see the list. |
21+| A workspace | **Settings → Runners**, `g1t.sh/<workspace>/-/runners` | Owners only. |
2222 | A project | **Settings → Runners**, `g1t.sh/<workspace>/<project>/settings/runners` | People with the Admin [role](/guides/access-and-roles/) on its repository |
2323
2424 A workspace's runners serve the repositories their [group](#groups) allows.
+16−11
272272 **Usage** card there with this month's spend.
273273
274274 The sidebar is one list, in groups: **Mission control**, the workspace's
275−**Overview** and **Explore**; its projects; what it builds and runs with
276−across them (**Agent fleet**, **Context**, **Memory**, **Security**,
277−**Guardrails**, [**Secrets and variables**](/guides/secrets-and-variables/),
278−[**Integrations**](/guides/integrations/) and
279−[**Webhooks**](/guides/webhooks/)); then **Usage**, what g1t's runs have
280−cost (see [usage and billing](/guides/usage-and-billing/)), **Support** and
275+**Overview** and **Explore**; its projects; the places work happens across
276+them (**Agent fleet**, **Context**, **Memory**, **Security** and
277+[**Packages**](/guides/packages/)); then who belongs (**Members**, and
278+**Teams** soon), **Usage**, what g1t's runs have cost (see
279+[usage and billing](/guides/usage-and-billing/)), **Support** and
281280 **Settings**. An item with an arrow opens a list of its own in the sidebar:
282−**Settings** slides over to the workspace's settings, and the row at the
283−top, **‹ Settings**, slides back:
281+**Settings** slides over to how the workspace is set up and connected, and
282+the row at the top, **‹ Settings**, slides back:
284283
285284 | Settings | Who | |
286285 | --- | --- | --- |
287286 | **General** | Owners | The icon, the display name, a one-line description and the address (the slug). |
288−| **Members** | Members | Who belongs, and their roles. Owners add and remove people, set the [base permission](/guides/access-and-roles/#the-base-permission), and see the **Outside collaborators** tab. |
289287 | **Repositories** | Members | The workspace's repositories. Owners also see **Recently deleted**, where a [deleted repository](/guides/managing-repositories/#restore-a-repository) can be restored, or purged, for 30 days. |
290288 | **Access tokens** | Members | The workspace's own tokens. Owners create and delete them. |
289+| **Guardrails** | Members | What agents may do and spend across the workspace. Owners change them. |
290+| [**Secrets and variables**](/guides/secrets-and-variables/) | Members | What runs and deployments are given. Owners change them. |
291+| **Runners** | Owners | The workspace's self-hosted machines, their groups and registration tokens. |
292+| [**Integrations**](/guides/integrations/) | Members | Model providers and connected services. Owners connect and remove them. |
293+| [**Webhooks**](/guides/webhooks/) | Members | Where the workspace's events are sent. Owners add and change them. |
291294 | **Billing and plans** | Members | [The g1t plan](/guides/usage-and-billing/#the-g1t-plan), [limits](/guides/usage-and-billing/#limits) and the statement. Owners start the plan, check a card, prepay and set limits. |
292295 | **Audit log** | Members | [Every action agents, people and tokens took](/guides/audit-log/). |
293296
294−Integrations, secrets and variables, webhooks and guardrails are in the
295−main list. Members see each; owners change them.
297+**Members** is in the main list, for every member to see; owners add and
298+remove people there, set the
299+[base permission](/guides/access-and-roles/#the-base-permission), and see
300+the **Outside collaborators** tab.
296301
297302 Opening a [project](/guides/projects/) slides the sidebar over to the
298303 project's own list, with **‹ All projects** at the top to go back. Its
+0−0

Binary or large file; its contents are not shown.

+5−1
227227 let role = actor.workspaces.iter().find(|m| m.slug.eq_ignore_ascii_case(&slug)).map(|m| m.role);
228228 match role {
229229 None => Ok(fail(FailureCode::NotFound, "There is no such workspace, or you are not a member of it.")),
230− Some(Role::Member) if manage => Ok(fail(FailureCode::Forbidden, format!("Only owners of {slug} can change its self-hosted runners."))),
230+ // A workspace's machines and their tokens are its owners' alone, to see as well as change.
231+ Some(Role::Member) => Ok(fail(
232+ FailureCode::Forbidden,
233+ format!("Only owners of {slug} can {} its self-hosted runners.", if manage { "change" } else { "see" }),
234+ )),
231235 Some(_) => Ok(Outcome::Ok(Place { workspace: slug, repo: None })),
232236 }
233237 }