Users, roles, and permissions
Verb-level access control โ every action is a permission, roles are groups of permissions, and one super admin always survives.
Managing multiple clusters
Run more than one Incus cluster from one control plane, each reached over its own scoped certificate, with per-capability degradation.
Networks and profiles
kixctl owns its bridge, profile, resolver, and edge by default, and registers your existing ones as read-only references it never mutates.
LAN reachability
Deployed apps are internal by default; reaching them from your LAN takes a resolver forward and a route, both in equipment kixctl does not own.
How kixctl accesses Incus
The control plane reaches the fabric over a restricted certificate scoped to one project and capped at operator โ it cannot escalate its own access.