Something went wrong. Try again.
Microservice to bring 2FA to self hosted PDSes
Something went wrong. Try again.
pds-gatekeeper dev_admin_rbac.yaml
2.5 kB · 71 lines
YAML
at main
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172# PDS Admin Team — Role-Based Access Control## This file defines which ATProto identities can perform admin operations# through pds-gatekeeper's admin portal. Each member authenticates via# ATProto OAuth (using their Bluesky/AT Protocol identity) and is granted# access only to the endpoints their roles permit.## Endpoint patterns:# - Exact match: "com.atproto.admin.getAccountInfo"# - Wildcard: "com.atproto.admin.*" (matches all admin endpoints)## Usage:# 1. Copy this file and customize for your team# 2. Set GATEKEEPER_ADMIN_RBAC_CONFIG=/path/to/your/admin_rbac.yaml# 3. Set PDS_ADMIN_PASSWORD=your-pds-admin-password# 4. Restart pds-gatekeeper# 5. Navigate to https://your-pds.example.com/admin/login
roles: pds-admin: description: "Full PDS administrator — all admin endpoints + account/invite creation" endpoints: - "com.atproto.admin.*" - "com.atproto.server.createInviteCode" - "com.atproto.server.createInviteCodes" - "com.atproto.server.createAccount" - "com.atproto.sync.requestCrawl"
moderator: description: "Content moderation — view accounts, manage takedowns and subject status" endpoints: - "com.atproto.admin.getAccountInfo" - "com.atproto.admin.getAccountInfos" - "com.atproto.admin.getSubjectStatus" - "com.atproto.admin.updateSubjectStatus" - "com.atproto.admin.sendEmail" - "com.atproto.admin.searchAccounts" - "com.atproto.admin.getInviteCodes"
invite-manager: description: "Invite code management — create and manage invite codes" endpoints: - "com.atproto.admin.getInviteCodes" - "com.atproto.admin.disableInviteCodes" - "com.atproto.admin.enableAccountInvites" - "com.atproto.admin.disableAccountInvites" - "com.atproto.server.createInviteCode" - "com.atproto.server.createInviteCodes"
members: # Replace these with your team members' DIDs. # Resolve a handle to its DID with: goat resolve {handle}
# Example: Full admin - did: "did:plc:rnpkyqnmsw4ipey6eotbdnnf" roles: - pds-admin - did: "did:plc:drgrihgw3oaavadu6oxmtpac" roles: - invite-manager
# # Example: Moderator only# - did: "did:plc:your-moderator-did-here"# roles:# - moderator## # Example: Someone with both moderator and invite manager roles# - did: "did:plc:your-team-member-did-here"# roles:# - moderator# - invite-manager