Cloudflare Access — RBAC groups (admin reference)¶
Hostnames:
| Host | Purpose |
|---|---|
docs.apexstem.org |
Mentor / parent / board shared wiki |
board.apexstem.org |
Board / finance / admin only — grants hub |
Model: Access is enforced by hostname (and optional path). Frontmatter roles: in markdown is documentation, not auto-enforced (adversarial review).
Maintain a copy of email → group in the board password manager or secretary’s offline sheet; do not commit member emails to git.
Access groups¶
| Group ID | Who | Where |
|---|---|---|
apex-admin |
2 technical admins | docs + board |
apex-board |
Trustees | docs + board |
apex-finance |
Treasurer + board chair | docs + board |
apex-mentors |
Adult mentors | docs only |
apex-parents-ridge-racers |
Ridge Racers parents/guardians | docs only |
apex-sponsors |
Active sponsors (optional Year 1) | Planned extranet — not board |
apex-volunteers |
General volunteers | Not wired Year 1 |
Year 1 rule: High-school volunteers use Freedcamp + email/PDF only (volunteer onboarding).
Deferred: apex-students-ridge-racers — default: parents access on behalf of under-13 students.
Hostname policies (recommended)¶
| Hostname | Allowed groups |
|---|---|
board.apexstem.org |
apex-board, apex-finance, apex-admin only |
docs.apexstem.org |
Board + mentors + parents (when invited) — no grants content |
Setup: board site Access · deploy board site
Deprecated (do not use for grants)¶
| Path prefix | Notes |
|---|---|
/internal/board/ on docs.apexstem.org |
Replaced by board.apexstem.org. Content excluded from main MkDocs build. |
Invite workflow¶
- Secretary receives name, email, role(s) from team_lead or board.
- Admin adds email to correct Access group(s) / app policies.
- Board/finance → invite to both
docs(optional) andboard. - Mentors/parents → invite to
docsonly — neverboard. - User completes role onboarding.
Offboarding: Remove from all Access apps same day.
Seat planning¶
Cloudflare Access free tier ≈ 50 seats. Count parents + mentors + board before inviting everyone.
If exceeded → plan Auth0 (Phase 3) or split parents to email-only updates without docs login.