# PDS Admin Team — Role-Based Access Control # # This file defines which ATProto identities can perform admin operations # through pds-gatekeeper's admin portal. Each member authenticates via # ATProto OAuth (using their Bluesky/AT Protocol identity) and is granted # access only to the endpoints their roles permit. # # Endpoint patterns: # - Exact match: "com.atproto.admin.getAccountInfo" # - Wildcard: "com.atproto.admin.*" (matches all admin endpoints) # # Usage: # 1. Copy this file and customize for your team # 2. Set GATEKEEPER_ADMIN_RBAC_CONFIG=/path/to/your/admin_rbac.yaml # 3. Set PDS_ADMIN_PASSWORD=your-pds-admin-password # 4. Restart pds-gatekeeper # 5. Navigate to https://your-pds.example.com/admin/login roles: pds-admin: description: "Full PDS administrator — all admin endpoints + account/invite creation" endpoints: - "com.atproto.admin.*" - "com.atproto.server.createInviteCode" - "com.atproto.server.createInviteCodes" - "com.atproto.server.createAccount" - "com.atproto.sync.requestCrawl" moderator: description: "Content moderation — view accounts, manage takedowns and subject status" endpoints: - "com.atproto.admin.getAccountInfo" - "com.atproto.admin.getAccountInfos" - "com.atproto.admin.getSubjectStatus" - "com.atproto.admin.updateSubjectStatus" - "com.atproto.admin.sendEmail" - "com.atproto.admin.searchAccounts" - "com.atproto.admin.getInviteCodes" invite-manager: description: "Invite code management — create and manage invite codes" endpoints: - "com.atproto.admin.getInviteCodes" - "com.atproto.admin.disableInviteCodes" - "com.atproto.admin.enableAccountInvites" - "com.atproto.admin.disableAccountInvites" - "com.atproto.server.createInviteCode" - "com.atproto.server.createInviteCodes" members: # Replace these with your team members' DIDs. # Resolve a handle to its DID with: goat resolve {handle} # Example: Full admin - did: "did:plc:rnpkyqnmsw4ipey6eotbdnnf" roles: - pds-admin - did: "did:plc:drgrihgw3oaavadu6oxmtpac" roles: - invite-manager # # Example: Moderator only # - did: "did:plc:your-moderator-did-here" # roles: # - moderator # # # Example: Someone with both moderator and invite manager roles # - did: "did:plc:your-team-member-did-here" # roles: # - moderator # - invite-manager