Uploaded image for project: 'OpenShift API for Data Protection'
  1. OpenShift API for Data Protection
  2. OADP-5043

Need specific examples of RBAC settings for installing OADP in multiple namespaces

XMLWordPrintable

    • 3
    • False
    • Hide

      None

      Show
      None
    • False
    • ToDo
    • Important
    • 8
    • 2.667
    • Very Likely
    • 0
    • None
    • Unset
    • Unknown
    • None

      Description of problem:

      While the documentation states the following, users are unclear on how to set up this RBAC settings concretely.

      https://docs.openshift.com/container-platform/4.16/backup_and_restore/application_backup_and_restore/installing/about-installing-oadp.html#about-installing-oadp-on-multiple-namespaces_about-installing-oadp

      By default, each OADP deployment has cluster-level access across namespaces. OpenShift Container Platform administrators need to review security and RBAC settings carefully and make any necessary changes to them to ensure that each OADP instance has the correct permissions.
      

      We need clear examples. For instance, here is the use case that some users are considering:

       

      TeamA: Installs OADP into namespace oadp-a, and wants to backup/restore namespace team-a, but don't want to allow backup/restore of other namespaces.
      TeamB: Installs OADP into namespace oadp-b, and wants to backup/restore namespace team-b, but don't want to allow backup/restore of other namespaces.
      

      Version-Release number of selected component (if applicable):

      How reproducible:

      Steps to Reproduce:
      1.
      2.
      3.

      Actual results:

      Expected results:

      Additional info:

       

      also update https://access.redhat.com/articles/5456281#can-i-install-oadp-into-multiple-openshift-projects-to-enable-project-owners-31 when this ticket is done.

       

      Slack: https://redhat-internal.slack.com/archives/C0144ECKUJ0/p1728968322617729?thread_ts=1728627599.380689&cid=C0144ECKUJ0

              rhn-support-shdeshpa Shruti Deshpande
              rhn-support-yuokada Yuki Okada
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: