Skip to content
English

Node tree and tags

Once there are many assets, two ways of organizing them are needed: a hierarchy (which environment, which system) and a cross-cutting mark (which machines get handled together). The node tree carries the first and can be granted on; tags carry the second and can be filtered on.

The node tree is on the left of the assets page and the asset table on the right, and clicking a node filters the table. Node actions live in the menu on the tree: add a child node, rename, move, grant on this node, delete.

  • Ten levels deep at most. Names cannot repeat within a level, and the same name under different parents is fine.
  • Moving asks for the target parent, and leaving it empty moves the node to the root level. Moving a node into its own descendant is stopped, and so is a move that would exceed the depth limit.
  • An asset can hang on several nodes, or on none. Assets on none are grouped under “ungrouped”.
  • Only an empty node, with no child nodes and no assets hanging directly on it, can be deleted. Before the deletion, the interface says how many authorizations and approver scopes are revoked along with it.

The table on the right includes the subtree by default, and can be switched to show only the assets hanging directly on the current node.

Granting on a node means “the assets of that node and all of its descendants”. New assets that later join the subtree are covered without another grant. Node grants, direct grants, and group grants combine as a union; there is no “deny” form. The authorization page shows the full path name for a node target, for example prod / kafka.

Users who are neither administrators nor auditors see a tree narrowed to the nodes holding assets they are authorized for, plus the chain of ancestors, and each node lists only the assets they are authorized for.

Pick an existing tag or type a new one in the tag field of the asset form. The system autocompletes as you type, and when an existing tag is written similarly it suggests using that one, so one concept does not split into several words. A tag holds no commas, runs to 64 characters, and an asset carries up to 20 of them.

On save the system normalizes the writing: whitespace removed, duplicates removed, and tags that differ only in case or composition form folded into the spelling that already exists.

The asset list filters by tag. Several tags are joined with “and”, matching is on the whole term and case-insensitive, and wildcards are matched literally. Each asset shows up to two tags in the list, with the rest folded into “+N”.

“Manage tags” in the toolbar of the assets page lists every tag with the number of assets using it, and can be searched. Renaming, merging (renaming to a name that already exists is a merge), and deleting happen here. Before it runs, the number of affected assets is shown and a second confirmation is asked for.

  • Deleting a node revokes the authorizations and approver scopes hanging on it in the same transaction, and the record holds how many were revoked with it.
  • Deleting a user group likewise reports and records how many were revoked with it.
  • Renaming, merging, and deleting a tag happen in a single transaction, and each affected asset leaves its own record carrying the operator’s identity.