Skip to main content
Run any Skill in Manus
with one click

rbac-fleet

Stars4
Forks2
UpdatedJuly 1, 2026 at 03:04

Apply RBAC changes across many ConfigHub Units at once with the cub-rbac CLI: bulk structured edits (fleet-edit) and override-preserving variant propagation from upstream (promote). Use for "add deletecollection to the developer role in every dev cluster", "remove the wildcard verb from this persona role fleet-wide", "add the oncall group to viewers across prod", "propagate the base RBAC change to all staging clones", "upgrade downstream RBAC units to their upstream", "which downstream units are behind their base?". Both are dry-run by default and require --commit + --change-desc; they never bypass ApplyGates and never apply to clusters. Not for a single Unit (use rbac-edit), not for inventory/queries (use rbac-audit / rbac-whocan), not for installing policy (use rbac-guardrails), not for rolling out to clusters (use cub-apply).

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly