Granting user access to extension resources by using custom role bindings
As a cluster administrator, you can manually create and configure role-based access control (RBAC) policies to grant user access to extension resources by using custom role bindings.
-
A cluster extension has been installed on your cluster.
-
You have a list of API groups and resource names, as described in "Finding API groups and resources exposed by a cluster extension".
-
If the installed cluster extension does not provide default cluster roles, manually create one or more roles:
-
Consider the use cases for the set of roles described in "Common default cluster roles for users".
For example, create one or more of the following
ClusterRoleobject definitions, replacing<cluster_extension_api_group>and<cluster_extension_custom_resource>with the actual API group and resource names provided by the installed cluster extension:Exampleview-custom-resource.yamlfileapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: view-custom-resource rules: - apiGroups: - <cluster_extension_api_group> resources: - <cluster_extension_custom_resources> verbs: - get - list - watchExampleedit-custom-resource.yamlfileapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: edit-custom-resource rules: - apiGroups: - <cluster_extension_api_group> resources: - <cluster_extension_custom_resources> verbs: - get - list - watch - create - update - patch - deleteExampleadmin-custom-resource.yamlfileapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: admin-custom-resource rules: - apiGroups: - <cluster_extension_api_group> resources: - <cluster_extension_custom_resources> verbs: - '*'Setting a wildcard (
*) in therules.verbsfield allows all actions on the specified resources. -
Create the cluster roles by running the following command for any YAML files you created:
$ oc create -f <filename>.yaml
-
-
Associate a cluster role to specific users or groups to grant them the necessary permissions for the resource by binding the cluster roles to individual user or group names:
-
Create an object definition for either a cluster role binding to grant access across all namespaces or a role binding to grant access within a specific namespace:
-
The following example cluster role bindings grant read-only
viewaccess to the custom resource across all namespaces:ExampleClusterRoleBindingobject for a userapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: view-custom-resource-binding subjects: - kind: User name: <user_name> roleRef: kind: ClusterRole name: view-custom-resource apiGroup: rbac.authorization.k8s.ioExampleClusterRoleBindingobject for a userapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: view-custom-resource-binding subjects: - kind: Group name: <group_name> roleRef: kind: ClusterRole name: view-custom-resource apiGroup: rbac.authorization.k8s.io -
The following role binding restricts
editpermissions to a specific namespace:ExampleRoleBindingobject for a userapiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: edit-custom-resource-edit-binding namespace: <namespace> subjects: - kind: User name: <username> roleRef: kind: Role name: custom-resource-edit apiGroup: rbac.authorization.k8s.io
-
-
Save your object definition to a YAML file.
-
Create the object by running the following command:
$ oc create -f <filename>.yaml
-