Help Center/ CodeArts Artifact/ User Guide/ Self-Hosted Repos (New)/ Configuring Repository Permissions
Updated on 2026-08-10 GMT+08:00

Configuring Repository Permissions

By default, new users in self-hosted repos have no permissions. You need to add them to a project and assign roles to them. Each role has different permissions. You can view role permissions on the CodeArts Artifact permissions page and edit user permissions as needed.

Constraints

  • By default, project administrators have all permissions and their permission scope cannot be modified.
  • Custom roles created in CodeArts Artifact do not have preset permissions. You can contact the project administrator to configure roles and permissions on corresponding resources.
  • By default, the project administrator, project manager, and test manager can assign permissions for other roles in self-hosted repos. If other roles can assign permissions, they can continue to configure permissions for other roles in self-hosted repos.

Prerequisites

  • You have created a CodeArts project.
  • You have added users to the CodeArts project and assigned roles to them. For details, see Adding Project Members.
  • To assign permissions to other roles in the self-hosted repo, you must have the Privilege Config permission. By default, the project administrator, project manager, and test manager roles have this permission.

Project-Level Permissions

  1. Log in as a user with the Privilege Config permission, and access the self-hosted repo.
  2. Choose Settings > General > Permissions from the navigation pane. The Permissions page is displayed. Different project roles have different operation permissions.
  3. In the Roles area, click the role you want to configure permissions, select CodeArts Artifact on the right, and click Edit at the bottom of the page. In the displayed page, select or deselect the required permissions.

    Table 1 Project-level permissions

    Role/Operation

    Create Repository

    Edit Repository

    Delete Repository

    Restore

    Permanently Delete

    Restore All

    Clear All

    Upload Package

    Download/View Package

    Delete/Redeploy Uploaded Package

    Project manager

    Product manager

    Test manager

    Operation manager

    System engineer

    Committer

    Developer

    Tester

    Participant

    Viewer

    CI/CD engineer

    Project administrator

    • Tenant administrators (IAM user with the Tenant Administrator permissions) can manage all projects of a tenant. Project creators who are not tenant administrators have the permissions listed in the preceding table.
    • IAM users created without being added to any groups do not have permissions. Administrators can assign permissions to these users on the IAM console. Then users can use cloud resources in the account based on the assigned permissions.
    • Custom roles do not have preset permissions. You can contact the administrator to grant permissions for the resources needed for your role.

  4. Click Save.

Repository-Level Permissions

CodeArts Artifact allows you to configure permissions on all self-hosted repos in a project. For details, see Project-Level Permissions.

You can also configure permissions for a single self-hosted repo.

To add or remove permissions for self-hosted repo members, perform the following steps:

  1. Access self-hosted repos using your Huawei Cloud account and select the target repository from the repository list.
  2. Click Settings on the right of the page.
  3. Click the Repository Permissions tab. The roles in the current project are displayed.
  4. In the Roles area, select or deselect permissions of the target role, and click Save.

    • By default, created self-hosted repos inherit the Permissions in Settings in the project. Any changes made to these role permissions in Permissions will be synced to the repo's permissions.
    • If you do not change the repository permission of a role in the self-hosted repo, any changes made on the Permissions page will be synchronized to the repository permission of the self-hosted repo as well.
    • If you change the repository permission of a role directly in the self-hosted repo, any changes made on the Permissions page will not be synchronized to the repository permission of the self-hosted repo. You need to change the permission of the role in the repo itself.

Tenant-Level Permissions

  1. Access self-hosted repos using your Huawei Cloud account and select the target repository from the repository list.
  2. Click Tenant in the lower-left corner to go to the self-hosted repo of the tenant.
  3. Select a self-hosted repo, click Settings on the right, and find the Repository Permissions tab.

    Different roles in the tenant space have different operation permissions, as shown in Table 2.
    Table 2 Tenant-level permissions

    Permission Description

    Role/Operation

    Edit Repository

    Delete Repository

    Restore Repository

    Physic Delete

    Upload

    Download/View

    Delete/Redeploy

    Import

    Export

    Tenant space owner

    Tenant space admin

    Tenant space user

    ×

    ×

    • The operation permissions of the tenant space owner cannot be modified.
    • For details about how to add members to a tenant space, see Adding Project Members.