Joe Cantwell
06/12/2025, 8:30 AMapiVersion: api.cerbos.dev/v1
rolePolicy:
role: "notaRealRole
parentRoles:
- group:default/admins
- group:default/employees
- group:default/users
rules:
- resource: "resource.action"
allowActions: ["*"]
condition:
match:
expr: P.attr.isemployee == true
- resource: resource.task
allowActions: ["*"]
condition:
match:
expr: P.attr.isemployee == true
- resource: resource.template
allowActions: ["*"]
condition:
match:
expr: P.attr.isemployee == true
Charith (Cerbos)
rolePolicy.role
doesn't have to be a real role but its value must be in the set of principal.roles
sent in the request.