Read time: 1 minute
Last edited: Oct 05, 2021
This topic explains how to specify different resources to use with custom roles, integrations access, and Rely Proxy access.
To learn more about how resources are structured within custom role policies, read Custom role concepts.
LaunchDarkly uses a resource specifier syntax to name resources or collections of resources. This is a precise, flexible taxonomy that lets you identify and control any resource in your LaunchDarkly project.
The pattern to specify a resource looks like this:
The example above shows two tags separated by a comma. Tags are optional. If you don't need to use any tags, you can omit the semicolon (
;) and all content following.
In the example below, we create a resource that names all of the projects in an account:
The resource syntax accepts globs and wildcards, so you can name collections of resources with
*. You can also name a specific project by its ID.
In the example below, we name a project by the
You can name sets of resources down to the tag level.
In the example below, we name all projects with the
The term "scoping" refers to identifying resources in relation to other resources and the hieriarchy of permissions that connects them.
Resources can be scoped within parent resources. For example, metrics are scoped within a project, and feature flags are scoped within a project and environment.
Name scoped resources by using the resource syntax structure depicted below:
In the following example, we name all feature flags across all environments:
In the example above,
proj/*:includes all named projects in the list of results.
env/*: includes all environments in the list of results.
flag/*: includes all flags in the list of results. This example will return very broad results because of how comprehensive its permissions are.
User permissions are specific to each resource type, and different types do not share or inherit permissions. For example, if you set user permissions for a project with the ID
proj/default, the user does not have the same permissions for the project's environments unless you also set user permissions for
For a more refined example, we could name all feature flags whose keys start with
Here is a reference list of all the supported resources in LaunchDarkly, and their scopes:
|Resource type||Resource scope||Written expression|
|Top-level resource. Projects have no parent resource.|
|A child resources of |
For a list of all actions available to each resource, read Using actions.