My understanding is that if a user has the ability to manage sites they inherit the ability to view and edit .env variables.

This coupling limits the ability to open up the Manage Sites (and Ploi in general) to a smaller audience that ideal for most businesses.

User story: I want t grant access to be able to run commands, view deploy logs, trigger deploys, clear opcache etc... without the ability to view secrets and prod keys stored in the .env

Segregate .env view/edit to its own standalone permission instead of inheriting from Manage Sites

1 total vote
Quick Actions
Activity
View recent activity and updates
Use arrow keys to navigate