Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7297

Need fine-grained roles for hosted cluster resources

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • Hosted Control Planes
    • None
    • None
    • Future Sustainability
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Fine-grained roles for hosted cluster resources

       

      I propose that the hypershift operator comes with some pre-defined roles so that users can bind users, groups and service accounts to specific roles to achieve fine-grained RBAC to manage a fleet of hosted clusters.

       

      For example, there should be 3 different roles that have difference access levels.

      • view
      • edit
      • admin

      There could be different personas with these roles like:

      • hosted cluster viewer, editor, admin
      • nodepool viewer, editor, admin
      • etc

       

      ACM is developing a unified way to manage remote cluster infrastructure resources such as OpenShift Virtualization VMs, hosted clusters, etc and having these pre-defined roles will help ACM and any individual that want to establish fine-grained RBAC for the users and admins in the organization.

              racedoro@redhat.com Ramon Acedo
              rokejungrh Roke Jung
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                None
                None