Roles for access are assigned through EWC IAM. Please check EWC Service Related Roles page here.
Regarding the specific roles for the container registry, please refer to the table below:
| ewc-app-admin | ewc-app-maintainer | ewc-app-user | |
|---|---|---|---|
| EWC Container Registry role | Project Admin | Maintainer | Guest |
Where:
- ProjectAdmin: When creating a new project, you will be assigned the “ProjectAdmin” role to the project. Besides read-write privileges, the “ProjectAdmin” also has some management privileges, such as adding and removing members, starting a vulnerability scan.
- Maintainer: Maintainer has elevated permissions beyond those of ‘Developer’ including the ability to scan images, view replications jobs, and delete images and helm charts.
- Guest: Guest has read-only privilege for a specified project. They can pull and retag images, but cannot push.
In addition, a user which is not logged in is considered anonymous:
- Anonymous: When a user is not logged in, the user is considered as an “Anonymous” user. An anonymous user has no access to private projects and has read-only access to public projects.