Skip to content

Cloudflare Access — RBAC groups (admin reference)

Hostnames:

Host Purpose
docs.apexstem.org Mentor / parent / board shared wiki
board.apexstem.org Board / finance / admin only — grants hub

Model: Access is enforced by hostname (and optional path). Frontmatter roles: in markdown is documentation, not auto-enforced (adversarial review).

Maintain a copy of email → group in the board password manager or secretary’s offline sheet; do not commit member emails to git.


Access groups

Group ID Who Where
apex-admin 2 technical admins docs + board
apex-board Trustees docs + board
apex-finance Treasurer + board chair docs + board
apex-mentors Adult mentors docs only
apex-parents-ridge-racers Ridge Racers parents/guardians docs only
apex-sponsors Active sponsors (optional Year 1) Planned extranet — not board
apex-volunteers General volunteers Not wired Year 1

Year 1 rule: High-school volunteers use Freedcamp + email/PDF only (volunteer onboarding).

Deferred: apex-students-ridge-racers — default: parents access on behalf of under-13 students.


Hostname Allowed groups
board.apexstem.org apex-board, apex-finance, apex-admin only
docs.apexstem.org Board + mentors + parents (when invited) — no grants content

Setup: board site Access · deploy board site

Deprecated (do not use for grants)

Path prefix Notes
/internal/board/ on docs.apexstem.org Replaced by board.apexstem.org. Content excluded from main MkDocs build.

Invite workflow

  1. Secretary receives name, email, role(s) from team_lead or board.
  2. Admin adds email to correct Access group(s) / app policies.
  3. Board/finance → invite to both docs (optional) and board.
  4. Mentors/parents → invite to docs only — never board.
  5. User completes role onboarding.

Offboarding: Remove from all Access apps same day.


Seat planning

Cloudflare Access free tier ≈ 50 seats. Count parents + mentors + board before inviting everyone.

If exceeded → plan Auth0 (Phase 3) or split parents to email-only updates without docs login.