Skip to content

Commit 2331334

Browse files
authored
[Access] Document tag permissions for targets with Access for Infrastructure (#33676)
* [Zero Trust] Document tag permissions for infrastructure targets
1 parent 5ace351 commit 2331334

2 files changed

Lines changed: 50 additions & 1 deletion

File tree

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
title: Simplified permissions for tagging targets with Access for Infrastructure
3+
description: Tag targets with only the Zero Trust Write API token permission.
4+
date: 2026-10-01
5+
products:
6+
- cloudflare-one
7+
- access
8+
---
9+
10+
You can now tag [targets](/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/#tag-targets) using only the `Zero Trust Write` API token permission. Previously, tagging targets through the API required both `Zero Trust Write` and `Tag Write` permissions on the API token.
11+
12+
This change applies to inline target tagging through the [Infrastructure Access Targets API](/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/). Tagging resources through the general [Resource Tagging API](/resource-tagging/) still requires the `Tag Admin`, `Tag Write`, or equivalent role.
13+
14+
For more information, refer to [Tag targets](/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/#tag-targets).

‎src/content/docs/cloudflare-one/access-controls/applications/non-http/infrastructure-apps.mdx‎

Lines changed: 36 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,14 @@ tags:
1111
- Authentication
1212
---
1313

14-
import { Badge, Details, Tabs, TabItem, Render } from "~/components";
14+
import {
15+
APIRequest,
16+
Badge,
17+
Details,
18+
Tabs,
19+
TabItem,
20+
Render,
21+
} from "~/components";
1522

1623
<Details header="Feature availability">
1724

@@ -164,6 +171,34 @@ To view all available filters, type `warp-cli target list --help`.
164171

165172
To revoke a user's access to all infrastructure targets, you can either [revoke the user from Zero Trust](/cloudflare-one/access-controls/access-settings/session-management/#per-user) or revoke their device. Cloudflare does not currently support revoking a user's session for a specific target.
166173

174+
## Tag targets
175+
176+
Attach key-value [resource tags](/resource-tagging/) to targets to organize and filter them or build [target criteria](#target-criteria) for your applications.
177+
178+
To tag a target, you need an API token with the `Zero Trust Write` [permission](/fundamentals/api/reference/permissions/). No additional tag-specific permissions are required.
179+
180+
To add tags to a target, make a `PUT` request to the [Infrastructure Access Targets](/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/update/) endpoint. Include a `tags` object:
181+
182+
<APIRequest
183+
path="/accounts/{account_id}/infrastructure/targets/{target_id}"
184+
method="PUT"
185+
json={{
186+
hostname: "infra-target-example",
187+
ip: {
188+
ipv4: {
189+
ip_addr: "198.51.100.10",
190+
virtual_network_id: "c77b744e-acc8-428f-9257-6878c046ed55",
191+
},
192+
},
193+
tags: {
194+
environment: "production",
195+
team: "platform",
196+
},
197+
}}
198+
/>
199+
200+
Each target supports one value per tag key. For more information on managing tags, refer to [Resource Tagging](/resource-tagging/how-to/manage-tags/).
201+
167202
## Granular target permissions
168203

169204
Infrastructure Access supports granular read permissions through [Cloudflare's role-based access control](/fundamentals/manage-members/roles/). Administrators can assign read-only roles scoped to specific targets instead of granting account-wide access. When a user with a scoped role calls the targets list API, the response is automatically filtered to only include the targets they have permission to view.

0 commit comments

Comments
 (0)