Features and capabilities

Human access, roles, policies, and durable records

Verified scope for built-in auth, LDAP/OIDC, roles, groups, access policy, and audit surfaces.

How should this content be used?Verified product behaviorDocumentation versionLatest

The behaviors on this page were matched to implementation or acceptance evidence in the stated source snapshot.

Identity and roles

Built-in sessions, LDAP, Google, and generic OIDC are available together with six fixed platform roles and local/LDAP groups.

Access and audit

User/group/anonymous subjects are bound to organization/project/repository scope. Administration, package usage, operation, and outbound records are stored in PostgreSQL.

Identity sources

Built-in users are managed in the platform. LDAP can map identity and group membership at sign-in, while Google and generic OIDC provide external sign-in flows. Provider claims, redirect URIs, group ownership, and user-disable behavior require target-environment acceptance.

Authorization layers

Platform roles govern administrative functions, while resource-scoped access policy governs actions on organizations, projects, and repositories. Repository sharing can provide visibility context but does not grant Upload or Download by itself; anonymous access also requires explicit policy scope.

  • Successful access with the least-privileged role and policy
  • Denial for an out-of-scope organization, project, or repository for the same user
  • Effective-access change when group membership is added and removed
  • Separation of an anonymous Proxy-only scenario from Hosted-publish denial

Purpose of records

Audit supports investigation of administrative and authorization changes; Package Usage tracks package access; Operation tracks long-running background work; Outbound supports upstream, identity, or intelligence connectivity investigation. Retention, access authorization, and external SIEM forwarding are organizational responsibilities.

Diagnostic-bundle security boundary

Support bundles require AdministerSystem. A bundle collects diagnostic records for the selected time window and redacts known authorization, cookie, credential, token, password, and secret patterns, but automatic redaction does not replace organizational human review before sharing.

Security responsibilities

External-provider secrets, LDAP bind material, and session or token material must come from a secret-management system and must not be written into documentation or source control. Published identity features do not guarantee MFA, certification, or a specific assurance level.