Uploaded image for project: 'Observability UI'
  1. Observability UI
  2. OU-568

Loki fine grained access permisson incompatible with requirements to access the observe "tab" in the admin console

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • Admin-Console
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • NEW
    • NEW

      As a user I want to be able to search logs from "all applications/user namspaces" in a cluster.   An administrator assigns the clusterRole "logging-all-application-logs-reader" [1]

      The expectation is that this role grants me access to "Observe / logs" 

      • so that I can search logs from all namespaces in a single window. 
        but this role alone is not enough permissions to access the higher level navigation of "observe" in the admin panel. 

      the expectation is that a user can be given the access to all application logs without having to be granted a "cluster admin" role.  

      [1] - https://docs.openshift.com/container-platform/4.16/observability/logging/log_storage/cluster-logging-loki.html#cluster-wide-access 

              gbernal@redhat.com Gabriel Bernal
              rhn-support-nigsmith Nigel Smith
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: