feat(coderd): gate org-member workspace elevation behind experiment - #26027
Merged
Conversation
Member
Author
This was referenced Jun 3, 2026
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 3, 2026 17:13
2bb6939 to
c91e381
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 3, 2026 20:48
c91e381 to
d1ee7c9
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
2 times, most recently
from
June 3, 2026 21:09
3bf0cd9 to
4347bf4
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 3, 2026 21:09
d1ee7c9 to
7813b1a
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
from
June 3, 2026 21:23
4347bf4 to
e4356f7
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
2 times, most recently
from
June 3, 2026 21:43
210be86 to
34ec9ef
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
2 times, most recently
from
June 3, 2026 21:56
00b5c1f to
0988f35
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
2 times, most recently
from
June 3, 2026 22:14
8e1cf4c to
d46be0c
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
from
June 3, 2026 22:14
0988f35 to
27102b3
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 3, 2026 22:20
d46be0c to
0e1c45b
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
2 times, most recently
from
June 3, 2026 22:29
e3705f7 to
6c14675
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 3, 2026 22:29
0e1c45b to
b78d140
Compare
Emyrk
marked this pull request as ready for review
June 3, 2026 23:03
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 14:19
b78d140 to
900ff1c
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
from
June 5, 2026 14:19
6c14675 to
5f27760
Compare
Emyrk
added a commit
that referenced
this pull request
Jun 5, 2026
<!-- Authored by Coder Agents on behalf of @Emyrk. --> Refs [PLAT-217](https://linear.app/codercom/issue/PLAT-217/rfc-for-gateway-accounts). Extracts an `organization-workspace-access` role so workspace elevation can be split off the organization-member floor without changing behavior. - New role holds the workspace-side resources currently granted by `organization-member`. - The `MinimumImplicitMember` floor preserves the existing behavior until #26027 shrinks it. - Prebuilds orchestrator inserts memberships via `dbauthz.AsSystemRestricted` and no longer needs `OrganizationMember` or `AssignOrgRole` grants. <details><summary>Agent context</summary> - `coderd/rbac/roles.go`: `OrgWorkspaceAccessMemberPerms()` grants `Workspace`, `WorkspaceDormant`, `File` (Create+Read), `ProvisionerDaemon` (Create+Read), and `Task`. Deliberate omissions (`Template`, `Group`, `WorkspaceProxy`, etc.) are documented inline. - `coderd/rbac/roles_test.go`: `orgWorkspaceAccessUser` is added to `requiredSubjects`. `UserProvisionerDaemons` is split into `UserProvisionerDaemonsCreate` and `UserProvisionerDaemonsUpdateDelete` because the new role grants Create+Read only and the test framework requires uniform pass/fail per case. - `codersdk/rbacroles.go`: exposes `RoleOrganizationWorkspaceAccess`. - `enterprise/coderd/prebuilds/membership.go`: `InsertOrganizationMember` runs under `dbauthz.AsSystemRestricted`. The orchestrator never acts with the elevation role; the membership row only exists so prebuilt workspaces have a valid owner. - `coderd/database/dbauthz/dbauthz.go`: drops the now-dead `OrganizationMember` and `AssignOrgRole` permissions from the prebuilds-orchestrator role and the orchestrator's entry in `assignRoles`. </details> --- <sub>Coder Agents on behalf of @Emyrk.</sub>
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 15:32
900ff1c to
9154d41
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
from
June 5, 2026 15:32
5f27760 to
bca7a5d
Compare
geokat
reviewed
Jun 5, 2026
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
from
June 5, 2026 18:59
bca7a5d to
c76dc3f
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 18:59
9154d41 to
fb90875
Compare
geokat
approved these changes
Jun 5, 2026
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
from
June 5, 2026 19:20
c76dc3f to
71515b0
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 19:20
fb90875 to
d265c34
Compare
Emyrk
force-pushed
the
gateway-accounts/test-subject-default-roles
branch
2 times, most recently
from
June 5, 2026 19:34
8f093d5 to
92e48cc
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 19:34
d265c34 to
4c0ab67
Compare
Emyrk
changed the base branch from
gateway-accounts/test-subject-default-roles
to
graphite-base/26027
June 5, 2026 20:01
Emyrk
force-pushed
the
graphite-base/26027
branch
from
June 5, 2026 20:01
92e48cc to
8a5e04e
Compare
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 20:01
4c0ab67 to
bb1bdc0
Compare
Adds RoleOptions.MinimumImplicitMember. When the minimum-implicit-member experiment is on, OrgMemberPermissions and OrgServiceAccountPermissions omit the workspace-ops elevation (OrgWorkspaceAccessMemberPerms). Members of the org then only have the floor unless granted organization-workspace-access via default_org_member_roles or direct assignment. Read once at startup from coderd.New. Flip the experiment, then restart coderd. Refs #25936.
Emyrk
force-pushed
the
gateway-accounts/floor-shrink-org-member
branch
from
June 5, 2026 20:02
bb1bdc0 to
5c49c19
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Refs #25936. Stacks on #26003.
Gates the workspace-ops elevation on
organization-memberandorganization-service-accountbehind theminimum-implicit-memberexperiment.organization-workspace-access.organization-workspace-accessfrom an org'sdefault_org_member_rolesactually removes workspace access from that org's members.Implementation notes
RoleOptions.MinimumImplicitMembermirrored into a package-levelatomic.Boolincoderd/rbac/object.go(same pattern asworkspaceACLDisabled/chatACLDisabled).OrgMemberPermissionsandOrgServiceAccountPermissionsare called from rolestore without access to api instance state, so the global is the existing escape hatch.ReloadBuiltinRolesstores the value.OrgMemberPermissionsandOrgServiceAccountPermissionsread it viaMinimumImplicitMember().coderd.Newreads the experiment viaexperiments.Enabled(codersdk.ExperimentMinimumImplicitMember)and passes it through.ReadExperiments(...)moved up so it's available before theReloadBuiltinRolescall.ReloadBuiltinRoleswidened to include the experiment, otherwise the option would never reach the rbac package on deployments that have noDisable*flags set.Coder Agents on behalf of @Emyrk.