> ## Documentation Index
> Fetch the complete documentation index at: https://namespace.so/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions

Namespace uses a resource-based permission model. Each API action is associated with a resource type
and optionally scoped to a specific resource ID.

The following lists all public resources and their available actions.

# Public Resources

The following resources and actions are publicly available in the Namespace API.

## artifact

Objects stored in a workspace, identified by a path and namespace.

| action | description |
| - | - |
| `create` | Upload a new artifact to the workspace. |
| `expire` | Mark an artifact for deletion. |
| `list` | List artifacts in the workspace. |
| `resolve` | Download or retrieve an artifact. |

## bazel

<h3 id="bazelcache">
  bazel/cache
</h3>

Managed Bazel remote cache for accelerating builds by storing and retrieving build artifacts.

| action | description |
| - | - |
| `ensure` | Provision cache instance and get endpoint credentials. |

<h3 id="bazelexecution">
  bazel/execution
</h3>

Managed Bazel remote execution (RBE) clusters for running build and test actions remotely.

| action | description |
| - | - |
| `ensure` | Provision execution cluster and get scheduler/storage endpoints. |
| `get` | Get an existing execution cluster's endpoints. |

## builder

Remote BuildKit instances that perform container image builds on behalf of a workspace.

| action | description |
| - | - |
| `access` | Connect to a running builder instance. |
| `ensure` | Provision or reuse a builder instance. |

## cache

<h3 id="cachegradle">
  cache/gradle
</h3>

Managed Gradle build cache for storing and retrieving build outputs.

| action | description |
| - | - |
| `ensure` | Set up and get Gradle cache endpoint credentials. |
| `read` | Retrieve artifacts from the Gradle cache. |
| `write` | Store artifacts in the Gradle cache. |

<h3 id="cachehttpcache">
  cache/httpcache
</h3>

Managed HTTP build cache, compatible with Bazel, sccache, and other HTTP-cache-compatible tools.

| action | description |
| - | - |
| `ensure` | Set up and get HTTP cache endpoint credentials. |
| `read` | Retrieve artifacts from the HTTP cache. |
| `write` | Store artifacts in the HTTP cache. |

<h3 id="cacheturborepo">
  cache/turborepo
</h3>

Managed Turborepo remote cache for storing and retrieving task-level build artifacts.

| action | description |
| - | - |
| `delete` | Delete all cached artifacts for a team. |
| `list` | List teams with cached artifacts. |
| `read` | Retrieve cached artifacts or check cache status. |
| `report` | Submit Turborepo analytics and build events. |
| `write` | Store artifacts in the Turborepo cache. |

## containerregistry

Registry-wide configuration, including default and per-repository image expiration policies.

| action | description |
| - | - |
| `configure` | Manage registry expiration policies. |

<h3 id="containerregistrydomain">
  containerregistry/domain
</h3>

Custom registry domains that grant read-only image pull access.

| action | description |
| - | - |
| `pull` | Pull images through a custom registry domain. |

<h3 id="containerregistryimage">
  containerregistry/image
</h3>

Individual container images within a repository, identified by digest.

| action | description |
| - | - |
| `delete` | Delete a container image by digest. |
| `get` | Get container image details. |
| `list` | List container images across repositories. |
| `update` | Update an image's expiration lifetime. |

<h3 id="containerregistryrepository">
  containerregistry/repository
</h3>

Named image repositories within the container registry.

| action | description |
| - | - |
| `delete` | Delete a repository and its contents. |
| `list` | List image repositories in the registry. |
| `pull` | Pull images from a repository. |
| `share` | Create a publicly accessible link to an image. |
| `unshare` | Revoke public access to a shared image. |

<h3 id="containerregistrytags">
  containerregistry/tags
</h3>

Tags and tag version history within a repository.

| action | description |
| - | - |
| `list` | List tags in a repository. |

## devbox

| action | description |
| - | - |
| `activate` | Start or resume a devbox session. |
| `create` | Create a new devbox. |
| `expire` | Delete a devbox. |
| `fetch` | Retrieve devbox details. |
| `list` | List devboxes in the workspace. |
| `update` | Update devbox metadata or configuration. |

<h3 id="devboximage">
  devbox/image
</h3>

| action | description |
| - | - |
| `expire` | Delete or expire a devbox image. |
| `fetch` | Retrieve devbox image details. |
| `list` | List devbox images in the workspace. |
| `wire` | Resolve a devbox image for use. |

## github

<h3 id="githubrunner-profile">
  github/runner-profile
</h3>

Configuration profiles for ephemeral GitHub Actions runners, defining instance shape, OS, cache volumes, and custom runner images.

| action | description |
| - | - |
| `create` | Create a new runner profile. |
| `delete` | Delete a runner profile. |
| `get` | Retrieve a specific runner profile. |
| `list` | List all runner profiles. |
| `update` | Update a runner profile. |

## ingress

Authenticated network access to an instance's exposed ports.

| action | description |
| - | - |
| `access` | Access an instance's exposed ports. |

## instance

Ephemeral compute environments for running containers, with support for Docker, Kubernetes, suspend/resume, and remote access.

| action | description |
| - | - |
| `create` | Create a new instance. |
| `destroy` | Permanently terminate an instance. |
| `dial_host` | Connect to an instance's host services. |
| `exec` | Execute a command inside an instance. |
| `get` | Retrieve an instance's details. |
| `list` | List all instances in the workspace. |
| `refresh` | Extend an instance's lifetime deadline. |
| `release` | Detach an instance from its unique tag. |
| `resume` | Wake a suspended instance. |
| `ssh` | Start an SSH session to an instance. |
| `suspend` | Pause an instance, snapshotting its state. |
| `wait` | Wait for an instance to become ready. |

<h3 id="instanceingress">
  instance/ingress
</h3>

Public internet ingress endpoints exposed from an instance.

| action | description |
| - | - |
| `list` | List ingress endpoints for an instance. |
| `register` | Expose a backend from an instance to the internet. |

<h3 id="instancenotification">
  instance/notification
</h3>

Lifecycle events representing instance status changes, such as running, terminated, or failed.

| action | description |
| - | - |
| `list` | List recent lifecycle events for instances. |

<h3 id="instanceo11yegress">
  instance/o11y/egress
</h3>

Egress requests observed from instance(s).

| action | description |
| - | - |
| `list` | List egress records (per-instance or aggregated) |

<h3 id="instanceo11ylogs">
  instance/o11y/logs
</h3>

Streaming and historical log access for instance workloads.

| action | description |
| - | - |
| `get` | Stream or fetch logs from an instance. |

<h3 id="instanceo11ymetrics">
  instance/o11y/metrics
</h3>

Time-series resource usage metrics for instances, including CPU, memory, I/O, and storage.

| action | description |
| - | - |
| `get` | Retrieve resource usage metrics for an instance. |

<h3 id="instanceo11yoom">
  instance/o11y/oom
</h3>

Out-of-memory (OOM) kill events detected within an instance.

| action | description |
| - | - |
| `list` | List OOM kill events for an instance. |

## network

<h3 id="networkfabricsegment">
  network/fabric/segment
</h3>

Isolated network segments enabling private connectivity between instances.

| action | description |
| - | - |
| `attach` | Connect to a private network segment. |

## tenant

Workspaces in the Namespace platform.

| action | description |
| - | - |
| `get` | Retrieve workspace details and configuration. |

<h3 id="tenantbuilder_config">
  tenant/builder\_config
</h3>

Builder configuration for a workspace, including default and per-platform build instance types.

| action | description |
| - | - |
| `get` | Retrieve workspace builder configuration. |
| `update` | Update workspace builder configuration. |

<h3 id="tenantpolicies">
  tenant/policies
</h3>

Policy configuration for a workspace, including compute quotas and feature flags.

| action | description |
| - | - |
| `get` | Retrieve workspace policy settings and quotas. |

<h3 id="tenantusage">
  tenant/usage
</h3>

Compute and storage resource usage tracking for a workspace.

| action | description |
| - | - |
| `get` | Retrieve usage summary for a workspace. |

## testing

<h3 id="testingtestlogs">
  testing/test/logs
</h3>

Streaming access to test execution logs for a specific test target.

| action | description |
| - | - |
| `stream` | Stream logs for a test target execution. |

<h3 id="testingtestresult">
  testing/test/result
</h3>

Individual test target results within a test run, including pass/fail status and duration.

| action | description |
| - | - |
| `list` | List test results within a run. |
| `push` | Submit test results for a target. |

<h3 id="testingtestrun">
  testing/test/run
</h3>

Top-level test execution sessions that group individual test results.

| action | description |
| - | - |
| `complete` | Mark a test run as finished. |
| `create` | Start a new test run. |
| `get` | Retrieve details of a test run. |
| `list` | List test runs. |

## token

<h3 id="tokenrevokable">
  token/revokable
</h3>

Long-lived, explicitly revokable access tokens scoped to a workspace, with a maximum lifetime of 1 year.

| action | description |
| - | - |
| `create` | Create a new revokable access token. |
| `list` | List revokable tokens for a workspace. |
| `refresh` | Ensure a token remains valid for at least a requested duration. |
| `revoke` | Revoke a token to prevent further use. |

## vault

<h3 id="vaultobject">
  vault/object
</h3>

Encrypted secret values stored in a workspace's vault, managed via the Vault API.

| action | description |
| - | - |
| `create` | Create a new vault object. |
| `delete` | Delete a vault object. |
| `describe` | Retrieve a vault object's metadata and decrypted value. |
| `list` | List vault objects in the workspace. |
| `update` | Add a new version to an existing vault object. |

## volume

Cache volumes (and their snapshot generations) used to persist and reuse data across instances and builds.

| action | description |
| - | - |
| `get` | Retrieve details for a cache volume, including destroyed snapshot generations. |
| `list` | List cache volumes and their tag summaries. |

<h3 id="volumepersistent">
  volume/persistent
</h3>

Persistent volumes that preserve data independently of instance lifecycles.

| action | description |
| - | - |
| `describe` | Retrieve persistent volume details. |
| `destroy` | Destroy persistent volumes by ID or tag. |
| `list` | List persistent volumes in the workspace. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.