cmind/tenants/v1/group_service.proto
Package: cmind.tenants.v1
Messages
Group
Group is a custom, named collection of users within a tenant — distinct from the tenant access ladder (TenantRole). Groups are usable as subjects when granting permissions on deployments (group#member in the FGA model). Managing a group — creating, deleting, adding and removing members — is a tenant-admin operation, so those RPCs gate on tenant:{tenant_id} can_admin. Reading is not: group#can_read admits the group's own members and the parent tenant's admins, so a member reads the groups it belongs to and who else is in them, and a tenant admin reads every group of the tenant. Both read RPCs gate on the model, so the rule lives with the rest of the authorization rather than in handler code.
| Field | Type | Number | Description |
|---|---|---|---|
id | string | 1 | |
tenantId | string | 2 | |
name | string | 3 | |
memberCount | uint32 | 4 | member_count is populated by List responses only. |
CreateGroupRequest
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
name | string | 2 |
CreateGroupResponse
| Field | Type | Number | Description |
|---|---|---|---|
group | Group | 1 |
DeleteGroupRequest
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
groupId | string | 2 |
DeleteGroupResponse
ListGroupsRequest
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
apiKeyAttachable | bool | 2 | Only the groups the caller may attach an API key to: its own groups, or every group for a tenant admin. |
ListGroupsResponse
| Field | Type | Number | Description |
|---|---|---|---|
groups | repeated Group | 1 |
GroupMember
| Field | Type | Number | Description |
|---|---|---|---|
userId | string | 1 | |
metadata | cmind.permissions.v1.UserMetadata | 2 | metadata is populated by List responses only. Absent when the user can no longer be resolved (deleted from the identity provider). |
ListGroupMembersRequest
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
groupId | string | 2 |
ListGroupMembersResponse
| Field | Type | Number | Description |
|---|---|---|---|
members | repeated GroupMember | 1 |
AddGroupMemberRequest
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
groupId | string | 2 | |
userId | string | 3 |
AddGroupMemberResponse
RemoveGroupMemberRequest
| Field | Type | Number | Description |
|---|---|---|---|
tenantId | string | 1 | |
groupId | string | 2 | |
userId | string | 3 |
RemoveGroupMemberResponse
Services
GroupService
CreateGroup
Creates a custom group in the tenant.
Request: CreateGroupRequest
Response: CreateGroupResponse
ListGroups
Lists the custom groups the caller may read, or with api_key_attachable the ones it may attach an API key to. The gate admits any tenant member, and the handler then narrows per object on group#can_read or group#can_attach_apikey.
Request: ListGroupsRequest
Response: ListGroupsResponse
DeleteGroup
Deletes a group.
Request: DeleteGroupRequest
Response: DeleteGroupResponse
ListGroupMembers
Lists a group's members. group#can_read admits the group's own members and the parent tenant's readers, so a group outside the caller's reach is refused before the handler runs.
Request: ListGroupMembersRequest
Response: ListGroupMembersResponse
AddGroupMember
Adds a user to a group.
Request: AddGroupMemberRequest
Response: AddGroupMemberResponse
RemoveGroupMember
Removes a user from a group.
Request: RemoveGroupMemberRequest
Response: RemoveGroupMemberResponse