# Introduction

## Overview

Exoway is revolutionizing cloud architecture by integrating the 'diagram as code' concept at the heart of its orchestration platform.&#x20;

Designed to simplify the deployment of production-ready internal platforms, this solution leverages [Model-Driven Engineering (MDE)](#user-content-fn-1)[^1] and artificial intelligence to enable efficient design, deployment, and management of cloud infrastructures and applications.&#x20;

With Exoway, engineers can now transform diagrams into operational cloud architectures in just a few minutes, offering unparalleled self-service control over the entire infrastructure.

## Quick links

{% content-ref url="/pages/faV2qR7vYIKDqmXCOzaK" %}
[Our Features](/overview/our-features)
{% endcontent-ref %}

## Get Started

We've put together some helpful guides for you to get setup with Exoway quickly and easily.

{% content-ref url="/pages/qYW645na1x3F1kAUFaVX" %}
[Project](/fundamentals/project)
{% endcontent-ref %}

{% content-ref url="/pages/Yugz5tcS4r4ZwNJdqHf6" %}
[Blueprint](/fundamentals/blueprint)
{% endcontent-ref %}

{% content-ref url="/pages/klNGsexLfCCTNjM7Pz6Z" %}
[RBAC](/fundamentals/rbac)
{% endcontent-ref %}

[^1]: Model Driven Engineering (MDE) is a software development methodology that focuses on creating and exploring domain models, which are conceptual models of all topics related to a problem-specific domain


# Our Features

**Features that save your time:**

* **Building the schema through drag-and-drop :** With its whiteboard system, visualize your entire infrastructure and spot potential issues at a glance, even before deployment.
* **Catalog of resources from your cloud provider :** Exoway integrates all the components from the cloud provider into its catalog. The two steps of schema in diagram and then building the architecture are now one and the same step!
* **Schema consistency check :** By integrating rules specific to each cloud, the platform allows you to avoid potential compatibility issues between components during deployment.
* **One project, multiple environments :** One blueprint = one schema = one environment for development, QA, staging, training, production. Your project can contain multiple blueprints, for better management of permissions and changes.
* **Modification history :** Need to roll back? Exoway keeps a complete history of changes to your infrastructure. With just one click, you can restore the version that best suits your needs.
* **Detect possible errors and failures :** The platform provides you with real-time feedback on compatibility issues, errors, and potential failures in your infrastructure and code repositories.
* **Control the financial cost per hour :** Exoway directly integrates the official catalog of each cloud provider. The tool provides you with real-time information on the cost of your infrastructure.
* **Check the carbon footprint of your infrastructure :** Exoway has developed an algorithm based on ADEME studies to calculate the carbon impact of your infrastructure according to the resources used from each cloud.
* **Add annotations and comments :**  For added flexibility, the solution allows you to annotate each component of your schema. A useful feature for better collaboration with your peers.
* **Control the roles of each user :** Assign differentiated roles for each user to avoid errors (it's human!) with [Role Based Access Control](#user-content-fn-1)[^1].
* **Export your schema as an image :** Need to present your architecture to your manager or client? Download a preview of the schema in JPG format, to integrate into your presentation.
* **Deployment event log :** Track the status of your deployment in real time. View statistics for each of your projects. Quickly identify anomalies.
* **Integration of observability statistics :** With the integration of your monitoring tool, track your metrics: CPU usage, memory usage, disk read/write, network I/O, Kubernetes pods, etc.
* **Simplified tracking of logs on your infrastructure** : Follow the logs on your infrastructure at a macro level with the integration of your preferred log management tool.
* **Automated security analyses on code repositories :** A security analysis is automatically triggered for each code repository. A report is sent to the user to detect any existing system vulnerabilities.
* **Secure authentications :** We have integrated all the necessary features to ensure the security of your architecture => mandatory two-factor authentication, recovery codes, and a history of account logins.

[^1]: Role-based access control (RBAC) refers to the idea of assigning permissions to users based on their role within an organization. It offers a simple, manageable approach to access management that is less prone to error than assigning permissions to users individually.


# Project


# Overview

A project on the Exoway platform offers you centralized management of your blueprints and strategies by environment.&#x20;

It provides key indicators on financial aspects, carbon emissions, and infrastructure vulnerability. Each project is defined by specific access rights and includes a name, a description, and a default tag used to label resources during deployment.&#x20;

This facilitates the monitoring and management of your cloud deployments.&#x20;

By default, a project is created upon your registration and is associated with your organization.

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/6kwq4lwhzk>" %}


# Manage a project

### Create a project

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/8komn94i5r>" %}

### Delete a project

{% hint style="danger" %}
You can only delete projects that were not automatically created during the setup of your organizations, for consistency purposes within the Exoway platform.
{% endhint %}

### Update a project

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/8komnq6s5r>" %}


# Limits

Here are the current limitations within the "project" section, some of which will be removed when features are added:

* Currently, integrating a project with third-party solutions (such as GitHub, Notion, etc.) is not supported.
* Setting up IAM[^1] (Identity and Access Management) directly from a project is not possible.
* There is no feature to compare blueprints and strategies with other components within a different project.
* Comparing information and statistics between two projects cannot be done.
* It is impossible to delete a project that has already created blueprints.
* Transferring a project to another organization is not supported.
* A project isolates blueprints and environments, meaning strategies applied cannot be shared with another existing project.

[^1]: IAM allows you to grant precise access to specific resources within your cloud provider while preventing access to other resources. IAM enables you to apply the principle of least privilege security, which states that no one should have more permissions than necessary.


# Blueprint


# Overview

The blueprint is a workspace that will enable you to create your schema or diagram for your cloud provider.&#x20;

There are several specifics to your blueprint:&#x20;

* The environment allows targeting the execution framework and realization of your schema. You can define rules for each environment in every project.&#x20;
* The type of blueprint currently lets you choose if your diagram will be infrastructure-oriented (with more options arriving soon).&#x20;

{% hint style="info" %}
Note: For now, the blueprint approach is **mono-cloud**, but we are working on developing a [**multi-cloud** ](#user-content-fn-1)[^1]version, which will expand your possibilities for creation.
{% endhint %}

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/qkqxgnxf1r>" %}

[^1]: "Multi-cloud" means multiple public clouds. A company that uses a multi-cloud deployment incorporates multiple public clouds from more than one cloud provider. Instead of a business using one vendor for cloud hosting, storage, and the full application stack, in a multi-cloud configuration they use several.


# Nodes


# Edges


# Security


# Deployment


# History & Rollback


# Organization


# Overview

Organizations are the top-level entity in Exoway. They are the primary way to manage access to Exoway.

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/6kwq491czk>" %}


# Manage an Organization

The organization section allows you to manage:&#x20;

* the information defining your organization,&#x20;
* the members of your organization along with their rights (see [RBAC](/fundamentals/rbac)),&#x20;
* and the subscribed licenses and their distribution within your organization.

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/er5z67lf6r>" %}


# Licences


# RBAC


# Overview

Role-Based Access Control (RBAC) is a central element of managing your projects within Exoway.&#x20;

RBAC revolves around three key components:&#x20;

* users
* scope
* roles

It offers you the ability to finely restrict user privileges regarding access to a project's components (blueprint, environments).&#x20;

With RBAC, you have the capability to maintain a secure and organized system that meets your unique requirements in your project.


# Roles

A role definition is a collection of permissions. It's typically just called a role. A role definition lists the actions that can be performed, such as read, write, and delete. Roles can be high-level, like "Owner", or specific, like "Read Only User" .

| Name           | Description                                                                    |
| -------------- | ------------------------------------------------------------------------------ |
| Owner          | Owner and creator of the organization.                                         |
| Administrator  | Administrator of the organization. They are designated as such by the "Owner". |
| Operator       | Developer or technician of the organization.                                   |
| Helpdesk       | Support role on projects.                                                      |
| Standard User  | Invited to work on a project by the organization.                              |
| Read Only User | Simple observer of the organization's technical activities on the platform.    |

### List of entities impacted by roles

| Entity       | Description                                                                                                                                                            |
| ------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Organization | Major entity of the application.                                                                                                                                       |
| User         | This is the user entity. It acts more as a subject than an object. It is the one that will be queried to determine if it has the right to access other entity-objects. |
| Project      | Framework for all the work within an organization. An organization can have multiple projects.                                                                         |
| Blueprint    | Workspace within a project. A project can have multiple blueprints.                                                                                                    |

### List of rights by object entity (also called Namespace)

Each namespace has different access rights to its functionalities. It's important to know that there are two types of rights: Those that encompass an organization and those that are specific to a project and/or a blueprint.&#x20;

The rights of the Project and Blueprint namespaces are of the latter. This allows targeting a project for a person invited to work on a specific project and prevents them from accessing others.

#### Organization

| Name              | Description                                                                                                                                                                                                          |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| access\_org       | Access the organization (this is not about reading, but access from a code perspective - e.g., A person who can only access one project of the organization must still have access to some organization code calls). |
| read\_org         | Read access to the organization.                                                                                                                                                                                     |
| edit\_org         | Edit the organization (This does not involve administrative changes).                                                                                                                                                |
| administrate\_org | Administer the organization (Role assignment - modification of organization information).                                                                                                                            |
| delete\_org       | Delete the organization (The default organization cannot be deleted).                                                                                                                                                |
| read\_project     | Read access to the organization's projects.                                                                                                                                                                          |
| create\_project   | Create a new project within the organization.                                                                                                                                                                        |
| edit\_project     | Make modifications to a project.                                                                                                                                                                                     |
| delete\_project   | Delete a project.                                                                                                                                                                                                    |
| share\_project    | Share a project.                                                                                                                                                                                                     |
| read\_blueprint   | Read access to the blueprints of the organization's projects.                                                                                                                                                        |
| create\_blueprint | Create a blueprint within a project.                                                                                                                                                                                 |
| edit\_blueprint   | Modify a blueprint.                                                                                                                                                                                                  |
| delete\_blueprint | Delete a blueprint.                                                                                                                                                                                                  |
| deploy\_blueprint | Deploy a blueprint.                                                                                                                                                                                                  |
| revert\_blueprint | Revert to a previous version of the blueprint.                                                                                                                                                                       |
| share\_blueprint  | Share a blueprint.                                                                                                                                                                                                   |

#### Project

| Name              | Description                               |
| ----------------- | ----------------------------------------- |
| read              | Read access to a specific project.        |
| create\_blueprint | Create a blueprint in a specific project. |
| edit              | Modify a specific project.                |
| delete            | Delete a specific project.                |

#### Blueprint

| Name   | Description                                           |
| ------ | ----------------------------------------------------- |
| read   | Read access to a specific blueprint.                  |
| edit   | Modify a specific blueprint.                          |
| delete | Delete a specific blueprint.                          |
| share  | Share a specific blueprint.                           |
| revert | Revert to a previous version of a specific blueprint. |
| deploy | Deploy a specific blueprint.                          |

## Who can do what?

### Organization <a href="#organization-1" id="organization-1"></a>

| access\_org    | read\_org      | edit\_org      | delete\_org    | administrate\_org |
| -------------- | -------------- | -------------- | -------------- | ----------------- |
| owners         | owners         | owners         | owners         | owners            |
| administrators | administrators | administrators | administrators |                   |
| operators      | operators      | operators      |                |                   |
| helpdesks      |                |                |                |                   |
| standartUsers  |                |                |                |                   |
| readonlyUsers  | readonlyUsers  |                |                |                   |

| read\_project  | create\_project | edit\_project  | delete\_project | share\_project |
| -------------- | --------------- | -------------- | --------------- | -------------- |
| owners         | owners          | owners         | owners          | owners         |
| administrators | administrators  | administrators | administrators  | administrators |
| operators      | operators       | operators      | operators       | operators      |
| readonlyUsers  |                 |                |                 |                |

| read\_blueprint | create\_blueprint | edit\_blueprint | delete\_blueprint | deploy\_blueprint | revert\_blueprint | share\_blueprint |
| --------------- | ----------------- | --------------- | ----------------- | ----------------- | ----------------- | ---------------- |
| owners          | owners            | owners          | owners            | owners            | owners            | owners           |
| administrators  | administrators    | administrators  | administrators    | administrators    | administrators    | administrators   |
| operators       | operators         | operators       | operators         | operators         | operators         | operators        |
| readonlyUsers   |                   |                 |                   |                   |                   |                  |

### Project <a href="#project-1" id="project-1"></a>

| read          | create\_blueprint | edit          | delete        | share         |
| ------------- | ----------------- | ------------- | ------------- | ------------- |
| helpdesks     | helpdesks         |               |               |               |
| standardUsers | standardUsers     | standardUsers | standardUsers | standardUsers |

### Blueprint <a href="#blueprint-1" id="blueprint-1"></a>

| read          | edit          | delete        | share         | deploy        | revert        |
| ------------- | ------------- | ------------- | ------------- | ------------- | ------------- |
| helpdesks     | helpdesks     |               |               |               |               |
| standardUsers | standardUsers | standardUsers | standardUsers | standardUsers | standardUsers |


# Scope

### Overview

Scopes are an important concept in Exoway as they are used to specify the exact level of access to resources that can be granted.

### Scopes vs permissions[​](https://www.ory.sh/docs/oauth2-oidc/overview/oauth2-concepts#scopes-vs-permissions) <a href="#scopes-vs-permissions" id="scopes-vs-permissions"></a>

What's the difference between scopes and permissions? Scopes define what the user is authorized to access in the organization of the owner. Permissions (RBAC, ACL) define what the user themselves are allowed to do.&#x20;

By using scopes, owners can control the level of access that users have to protected resources. Permissions ensure a user has access to their resources only, not the resources of other users.


# Invite an user

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/dkd32l8b9p>" %}


# Clouds


# Overview


# For Cloud Architect

{% hint style="info" %}
**Good to know:** depending on the product you're building, it can be useful to explicitly document use cases. Got a product that can be used by a bunch of people in different ways? Maybe consider splitting it out!
{% endhint %}

## GitHub Integrations

Cras mattis consectetur purus sit amet fermentum. Praesent commodo cursus magna, vel scelerisque nisl consectetur et.

{% tabs %}
{% tab title="Installing" %}
Sed posuere consectetur est at lobortis. Integer posuere erat a ante venenatis dapibus posuere velit aliquet. Aenean lacinia bibendum nulla sed consectetur. Maecenas sed diam eget risus varius blandit sit amet non magna.

```
string | ComponentClass<any, any> | FunctionComponent<any>
```

{% endtab %}

{% tab title="Second tab" %}
Maecenas faucibus mollis interdum. Donec id elit non mi porta gravida at eget metus. Donec ullamcorper nulla non metus auctor fringilla. Donec sed odio dui. Donec ullamcorper nulla non metus auctor fringilla.
{% endtab %}
{% endtabs %}


# Introduction

## Vue d'ensemble

Exoway révolutionne l'architecture cloud en intégrant le concept de 'diagramme en tant que code' au cœur de sa plateforme d'orchestration.

Conçu pour simplifier le déploiement de plateformes internes prêtes à l'emploi, cette solution tire parti de l'[Ingénierie Dirigée par les Modèles (IDM)](#user-content-fn-1)[^1] et de l'intelligence artificielle pour permettre une conception, un déploiement et une gestion efficaces des infrastructures cloud et des applications.

Avec Exoway, les ingénieurs peuvent désormais transformer des diagrammes en architectures cloud opérationnelles en seulement quelques minutes, offrant un contrôle en libre-service sans précédent sur l'ensemble de l'infrastructure.

## Liens rapides

{% content-ref url="/pages/faV2qR7vYIKDqmXCOzaK" %}
[Nos fonctionnalités](/fr/vue-densemble/nos-fonctionnalites)
{% endcontent-ref %}

## Pour Commencer

Nous avons préparé pour vous des guides pratiques pour vous permettre de vous installer rapidement et facilement sur Exoway.

{% content-ref url="/pages/qYW645na1x3F1kAUFaVX" %}
[Projet](/fr/fondamentaux/projet)
{% endcontent-ref %}

{% content-ref url="/pages/Yugz5tcS4r4ZwNJdqHf6" %}
[Blueprint](/fr/fondamentaux/blueprint)
{% endcontent-ref %}

{% content-ref url="/pages/klNGsexLfCCTNjM7Pz6Z" %}
[RBAC](/fr/fondamentaux/rbac)
{% endcontent-ref %}

[^1]: L'Ingénierie Dirigée par les Modèles (IDM) est une méthodologie de développement de logiciels qui se concentre sur la création et l'exploration de modèles de domaine, qui sont des modèles conceptuels de tous les sujets relatifs à un domaine spécifique au problème.


# Nos fonctionnalités

### Fonctionnalités qui vous font gagner du temps :

* **Construction du schéma par glisser-déposer :** Avec son système de tableau blanc, visualisez toute votre infrastructure et identifiez les problèmes potentiels en un coup d'œil, même avant le déploiement.
* **Catalogue de ressources de votre fournisseur de cloud :** Exoway intègre tous les composants du fournisseur de cloud dans son catalogue. Les deux étapes, schématisation dans un diagramme puis construction de l'architecture, ne font maintenant plus qu'une !
* **Vérification de la cohérence du schéma :** En intégrant des règles spécifiques à chaque cloud, la plateforme vous permet d'éviter d'éventuels problèmes de compatibilité entre les composants lors du déploiement.
* **Un projet, plusieurs environnements :** Un modèle = un schéma = un environnement pour le développement, le contrôle qualité (QA), la mise en scène, la formation, la production. Votre projet peut contenir plusieurs modèles, permettant une meilleure gestion des permissions et des changements.
* **Historique des modifications :** Besoin de revenir en arrière ? Exoway conserve un historique complet des modifications apportées à votre infrastructure. En un seul clic, vous pouvez restaurer la version qui répond le mieux à vos besoins.
* **Détection de possibles erreurs et défaillances :** La plateforme vous fournit un retour en temps réel sur les problèmes de compatibilité, les erreurs et les éventuels échecs dans votre infrastructure et vos dépôts de code.
* **Contrôlez le coût financier par heure :** Exoway intègre directement le catalogue officiel de chaque fournisseur de cloud. L'outil vous fournit des informations en temps réel sur le coût de votre infrastructure.
* **Vérifiez l'empreinte carbone de votre infrastructure :** Exoway a développé un algorithme basé sur des études de l'ADEME pour calculer l'impact carbone de votre infrastructure selon les ressources utilisées de chaque cloud.
* **Authentifications sécurisées :** Nous avons intégré toutes les fonctionnalités nécessaires pour garantir la sécurité de votre architecture => authentification à deux facteurs obligatoire, codes de récupération et historique des connexions au compte.
* **Analyses de sécurité automatisées sur les dépôts de code :** Une analyse de sécurité est automatiquement déclenchée pour chaque dépôt de code. Un rapport est envoyé à l'utilisateur pour détecter toute vulnérabilité existante du système.
* **Suivi simplifié des journaux sur votre infrastructure :** Suivez les journaux de votre infrastructure à un niveau macro avec l'intégration de votre outil de gestion de journaux préféré.
* **Intégration de statistiques d'observabilité :** Avec l'intégration de votre outil de surveillance, suivez vos métriques : utilisation du CPU, utilisation de la mémoire, lecture/écriture sur le disque, I/O réseau, pods Kubernetes, etc.
* **Journal des événements de déploiement :** Suivez le statut de votre déploiement en temps réel. Consultez les statistiques pour chacun de vos projets. Identifiez rapidement les anomalies.
* **Exportez votre schéma sous forme d'image :** Besoin de présenter votre architecture à votre manager ou client ? Téléchargez un aperçu du schéma au format JPG, pour l'intégrer dans votre présentation.
* **Contrôle d'accès basé sur les rôles :** Contrôlez les rôles de chaque utilisateur : Attribuez des rôles différenciés à chaque utilisateur pour éviter les erreurs (c'est humain !)&#x20;
* **Ajout d'annotations et de commentaires :** Pour plus de flexibilité, la solution vous permet d'annoter chaque composant de votre schéma. Une fonctionnalité utile pour une meilleure collaboration avec vos pairs.


# Projet


# Vue d'ensemble

Lors de votre inscription, un projet est automatiquement créé et associé à votre organisation. Cela facilite le suivi et la gestion de vos déploiements cloud.&#x20;

Il fournit des indicateurs clés sur les aspects financiers, les émissions de carbone et la vulnérabilité de l'infrastructure.&#x20;

Chaque projet est défini par des droits d'accès spécifiques et comprend un nom, une description et une étiquette par défaut utilisée pour étiqueter les ressources lors du déploiement.&#x20;

Un projet sur la plateforme Exoway vous offre une gestion centralisée de vos plans et stratégies par environnement.

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/6kwq4lwhzk>" %}


# Gérer un projet

### Ajouter un projet

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/8komn94i5r>" %}

### Supprimer un projet

{% hint style="danger" %}
Sur la plateforme Exoway, vous pouvez uniquement supprimer les projets qui n'ont pas été créés automatiquement lors de la configuration de vos organisations, afin de garantir la cohérence.
{% endhint %}

### Modifier un projet

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/8komnq6s5r>" %}


# Limites

Voici les limitations actuelles au sein de la partie "projet", certaines seront supprimées lors de l'ajout de fonctionnalités :&#x20;

* Un projet cloisonne les blueprint et les environnements, ainsi les stratégies appliquées ne peuvent pas être transmises à un autre projet existant.
* Il n'est pas possible de transmettre un projet à une autre organisation.
* Il n'est pas possible de supprimer un projet ayant des blueprint de créer.
* La comparaison d'informations et de statistiques entre deux projets n'est pas possible.
* Il n'y a pas de comparaison des blueprints et des stratégies entre d'autres composants appartenant à un autre projet.
* Il n'est pas possible de définir les [IAM ](#user-content-fn-1)[^1]depuis un projet.
* La liaison d'un projet avec des solutions tierces (github, notion ...) n'est pas encore possible.

[^1]: IAM vous permet d'accorder un accès précis à des ressources spécifiques au sein de votre fournisseur de cloud tout en empêchant l'accès à d'autres ressources. IAM vous permet d'appliquer le principe de la sécurité du moindre privilège, qui stipule que personne ne devrait disposer de plus de permissions que nécessaire.


# Blueprint


# Vue d'ensemble

Le blueprint est un espace de travail qui vous permettra de créer votre schéma ou diagramme pour votre fournisseur de cloud.

Il y a plusieurs spécificités à votre plan :

* L'environnement permet de cibler le cadre d'exécution et la réalisation de votre schéma. Vous pouvez définir des règles pour chaque environnement dans chaque projet.
* Le type de plan actuellement disponible vous permet de choisir si votre diagramme sera orienté infrastructure (avec plus d'options à venir prochainement).

{% hint style="info" %}
Note : Pour le moment, l'approche des blueprints est **mono-cloud**, mais nous travaillons au développement d'une version [**multi-cloud**](#user-content-fn-1)[^1], ce qui élargira vos possibilités de création.
{% endhint %}

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/qkqxgnxf1r>" %}

[^1]: "Multi-cloud" signifie plusieurs clouds publics. Une entreprise qui utilise un déploiement multi-cloud incorpore plusieurs clouds publics de plus d'un fournisseur de cloud. Au lieu qu'une entreprise utilise un seul vendeur pour l'hébergement cloud, le stockage, et la pile d'applications complète, dans une configuration multi-cloud, elle utilise plusieurs.


# Noeuds


# Liaisons


# Sécurité


# Déploiement


# Historique & Retour-en-Arrière


# Organisation


# Vue d'ensemble

Les organisations sont l'entité de niveau supérieur dans Exoway. Elles constituent le principal moyen de gérer l'accès à Exoway.

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/6kwq491czk>" %}


# Gérer une Organisation

La partie organisation vous permet de gérer :

* les informations qui définissent votre organisation,&#x20;
* les membres de votre organisation ainsi que leurs droits (voir [RBAC](/fr/fondamentaux/rbac))
* et les licences souscrites et leurs répartitions dans votre organisation

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/er5z67lf6r>" %}


# Licenses


# RBAC


# Vue d'ensemble

Le contrôle d'accès basé sur les rôles (RBAC) est un élément central de la gestion de vos projets au sein d'Exoway.

RBAC s'articule autour de trois composants clés :

* users
* scope
* roles

Il vous offre la possibilité de restreindre finement les privilèges des utilisateurs concernant l'accès aux composants d'un projet (blueprint, environnements).

Avec RBAC (Role-Based Access Control, ou Contrôle d'Accès Basé sur les Rôles en français), vous disposez de la capacité de maintenir un système sécurisé et organisé qui répond à vos exigences uniques dans votre projet.


# Roles

Une définition de rôle est un ensemble d'autorisations. Il est généralement simplement appelé un rôle. Une définition de rôle énumère les actions qui peuvent être effectuées, telles que lire, écrire et supprimer. Les rôles peuvent être de haut niveau, comme "Owner", ou spécifiques, comme "Read Only User".

| Name           | Description                                                                       |
| -------------- | --------------------------------------------------------------------------------- |
| Owner          | Propriétaire et créateur de l'organisation.                                       |
| Administrator  | Administrateur de l'organisation. Il est désigné comme tel par le "Propriétaire". |
| Operator       | Développeur ou technicien de l'organisation.                                      |
| Helpdesk       | Rôle de soutien dans les projets.                                                 |
| Standard User  | Invité à travailler sur un projet par l'organisation.                             |
| Read Only User | Observateur simple des activités techniques de l'organisation sur la plateforme.  |

### Liste des entités impactées par les rôles

| Entity       | Description                                                                                                                                                 |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Organization | Entité principale de l'application.                                                                                                                         |
| User         | L'entité utilisateur sert davantage de sujet que d'objet. Elle est celle qui sera interrogée pour déterminer si elle a le droit d'accéder à d'autres objets |
| Project      | Cadre pour tout le travail au sein d'une organisation. Une organisation peut avoir plusieurs projets.                                                       |
| Blueprint    | Espace de travail au sein d'un projet. Un projet peut contenir plusieurs plans.                                                                             |

#### Liste des droits par entité d'objet (également appelée Espace de noms)

Les droits des espaces de noms Project et Blueprint relèvent de ce dernier. Cela permet de cibler un projet pour une personne invitée à travailler sur un projet spécifique et l'empêche d'accéder aux autres projets.&#x20;

Chaque espace de nom possède différents droits d'accès à ses fonctionnalités. Il est important de savoir qu'il existe deux types de droits : ceux qui englobent une organisation et ceux qui sont spécifiques à un projet et/ou un blueprint.

#### Organization

| Name              | Description                                                                                                                                                                                                                                              |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| access\_org       | Accéder à l'organisation (il ne s'agit pas de lire, mais d'accéder du point de vue du code - par exemple, une personne qui ne peut accéder qu'à un seul projet de l'organisation doit toujours avoir accès à certains appels de code de l'organisation). |
| read\_org         | Accès en lecture à l'organisation.                                                                                                                                                                                                                       |
| edit\_org         | Modifier l'organisation (Cela n'implique pas de changements administratifs).                                                                                                                                                                             |
| administrate\_org | Administrer l'organisation (Attribution de rôles - modification des informations de l'organisation).                                                                                                                                                     |
| delete\_org       | Supprimer l'organisation (L'organisation par défaut ne peut pas être supprimée).                                                                                                                                                                         |
| read\_project     | Accès en lecture aux projets de l'organisation.                                                                                                                                                                                                          |
| create\_project   | Créer un nouveau projet au sein de l'organisation.                                                                                                                                                                                                       |
| edit\_project     | Faire des modifications à un projet.                                                                                                                                                                                                                     |
| delete\_project   | Supprimer un projet.                                                                                                                                                                                                                                     |
| share\_project    | Partager un projet.                                                                                                                                                                                                                                      |
| read\_blueprint   | Accès en lecture aux plans des projets de l'organisation.                                                                                                                                                                                                |
| create\_blueprint | Créer un blueprint dans un projet.                                                                                                                                                                                                                       |
| edit\_blueprint   | Modifier un blueprint.                                                                                                                                                                                                                                   |
| delete\_blueprint | Supprimer un blueprint.                                                                                                                                                                                                                                  |
| deploy\_blueprint | Deployer un blueprint.                                                                                                                                                                                                                                   |
| revert\_blueprint | Revenir à une version précédente du plan.                                                                                                                                                                                                                |
| share\_blueprint  | Partager un blueprint.                                                                                                                                                                                                                                   |

#### Project

| Name              | Description                                |
| ----------------- | ------------------------------------------ |
| read              | Accès en lecture à un projet spécifique.   |
| create\_blueprint | Créer un schéma dans un projet spécifique. |
| edit              | Modifier un projet spécifique.             |
| delete            | Supprimer un projet spécifique.            |

#### Blueprint

| Name   | Description                                                 |
| ------ | ----------------------------------------------------------- |
| read   | Accès en lecture à un Blueprint spécifique.                 |
| edit   | Modifier un blueprint spécifique.                           |
| delete | Supprimer un blueprint spécifique.                          |
| share  | Partager un blueprint spécifique.                           |
| revert | Revenir à une version précédente d'un blueprint spécifique. |
| deploy | Déployer un blueprint précis.                               |

## Who can do what?

### Organization <a href="#organization-1" id="organization-1"></a>

| access\_org    | read\_org      | edit\_org      | delete\_org    | administrate\_org |
| -------------- | -------------- | -------------- | -------------- | ----------------- |
| owners         | owners         | owners         | owners         | owners            |
| administrators | administrators | administrators | administrators |                   |
| operators      | operators      | operators      |                |                   |
| helpdesks      |                |                |                |                   |
| standartUsers  |                |                |                |                   |
| readonlyUsers  | readonlyUsers  |                |                |                   |

| read\_project  | create\_project | edit\_project  | delete\_project | share\_project |
| -------------- | --------------- | -------------- | --------------- | -------------- |
| owners         | owners          | owners         | owners          | owners         |
| administrators | administrators  | administrators | administrators  | administrators |
| operators      | operators       | operators      | operators       | operators      |
| readonlyUsers  |                 |                |                 |                |

| read\_blueprint | create\_blueprint | edit\_blueprint | delete\_blueprint | deploy\_blueprint | revert\_blueprint | share\_blueprint |
| --------------- | ----------------- | --------------- | ----------------- | ----------------- | ----------------- | ---------------- |
| owners          | owners            | owners          | owners            | owners            | owners            | owners           |
| administrators  | administrators    | administrators  | administrators    | administrators    | administrators    | administrators   |
| operators       | operators         | operators       | operators         | operators         | operators         | operators        |
| readonlyUsers   |                   |                 |                   |                   |                   |                  |

### Project <a href="#project-1" id="project-1"></a>

| read          | create\_blueprint | edit          | delete        | share         |
| ------------- | ----------------- | ------------- | ------------- | ------------- |
| helpdesks     | helpdesks         |               |               |               |
| standardUsers | standardUsers     | standardUsers | standardUsers | standardUsers |

### Blueprint <a href="#blueprint-1" id="blueprint-1"></a>

| read          | edit          | delete        | share         | deploy        | revert        |
| ------------- | ------------- | ------------- | ------------- | ------------- | ------------- |
| helpdesks     | helpdesks     |               |               |               |               |
| standardUsers | standardUsers | standardUsers | standardUsers | standardUsers | standardUsers |


# Scope

### Vue d'ensemble

Les scopes (ou étendues d'accès) sont un concept important dans Exoway, car ils sont utilisés pour spécifier le niveau exact d'accès aux ressources qui peut être accordé.

### Scopes vs permissions[​](https://www.ory.sh/docs/oauth2-oidc/overview/oauth2-concepts#scopes-vs-permissions) <a href="#scopes-vs-permissions" id="scopes-vs-permissions"></a>

La différence entre les portées (scopes) et les permissions repose sur ce que l'utilisateur est autorisé à accéder au sein de l'organisation du propriétaire pour les portées, tandis que les permissions (RBAC, ACL) définissent ce que l'utilisateur lui-même est autorisé à faire.

En utilisant les scopes, les propriétaires peuvent contrôler le niveau d'accès que les utilisateurs ont sur les ressources protégées. Les permissions assurent qu'un utilisateur a accès uniquement à ses propres ressources, et non aux ressources des autres utilisateurs.


# Inviter un utilisateur

{% @guideflow/guideflow-embed requestedUrl="<https://app.guideflow.com/player/dkd32l8b9p>" %}


# Clouds


# Vue d'ensemble


# For Cloud Architect

{% hint style="info" %}
**Good to know:** depending on the product you're building, it can be useful to explicitly document use cases. Got a product that can be used by a bunch of people in different ways? Maybe consider splitting it out!
{% endhint %}

## GitHub Integrations

Cras mattis consectetur purus sit amet fermentum. Praesent commodo cursus magna, vel scelerisque nisl consectetur et.

{% tabs %}
{% tab title="Installing" %}
Sed posuere consectetur est at lobortis. Integer posuere erat a ante venenatis dapibus posuere velit aliquet. Aenean lacinia bibendum nulla sed consectetur. Maecenas sed diam eget risus varius blandit sit amet non magna.

```
string | ComponentClass<any, any> | FunctionComponent<any>
```

{% endtab %}

{% tab title="Second tab" %}
Maecenas faucibus mollis interdum. Donec id elit non mi porta gravida at eget metus. Donec ullamcorper nulla non metus auctor fringilla. Donec sed odio dui. Donec ullamcorper nulla non metus auctor fringilla.
{% endtab %}
{% endtabs %}


