permissions attribute is a set; reordering does not produce a diff.
Example — account-scoped read-only
Example — project-scoped VM operator
Argument reference
Required
Optional
Attribute reference (computed)
Lifecycle
Importing existing roles
Permissions
The API key managing roles needsrole.create, role.manage, and role.delete at the account level. The system role Account Admin grants all of these.
Data sources
Related
raff_member
Account-scoped members get account-scoped roles.
raff_project_member
Project-scoped members get project-scoped roles.
CLI: raff permission list
Browse the permission catalog.