You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/en/cloud/security/roles.md
+121-1Lines changed: 121 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,12 @@
1
1
---
2
2
title: Roles
3
3
description: >
4
-
A short lead description about this content page. It can be **bold** or _italic_ and can be split over multiple paragraphs.
4
+
Roles map permissions to users. Roles contain any number of keychains, which contain any number of keys (permissions). Assign roles to users to grant permissions.
5
5
date: 2023-10-30
6
6
categories: [Security]
7
7
tags: [roles, permissions]
8
8
---
9
+
Roles map permissions to users. Roles contain any number of keychains, which contain any number of keys (permissions). Assign roles to users to grant permissions.
9
10
10
11
## Provider Admin Role
11
12
@@ -22,22 +23,141 @@ tags: [roles, permissions]
22
23
- Applicable to platform engineering team and on-prem users.
23
24
24
25
**Who can assign this role?**
26
+
25
27
- Provider Admins
26
28
27
29
**When this role first assigned?**
30
+
28
31
- On ☁️ boot-up (using build args)
29
32
30
33
**How many instances of these roles?**
34
+
31
35
- Min: 1, Max: many (based on plan)
32
36
33
37
**Who can remove assignment of this role?**
38
+
34
39
- Provider Admins
35
40
36
41
**What permissions does this role have?**
42
+
37
43
- Can perform CRUD on all resources
44
+
45
+
{{% /card %}}
46
+
{{< /cardpane >}}
47
+
48
+
## Organization Roles
49
+
50
+
{{< cardpane >}}
51
+
{{% card header="Organization Adminstrator" %}}
52
+
53
+
**What is the purpose of this role?**
54
+
55
+
- Administration of an organization
56
+
57
+
**Who can assign this role?**
58
+
59
+
- The Organization Owner
60
+
61
+
**When this role first assigned?**
62
+
63
+
- Creation of new organization or User Account creation
64
+
65
+
**How many instances of these roles?**
66
+
67
+
- Min: 1, Max: many (based on plan)
68
+
- By default, the first Organization Admin is the owner (the creator of the organization).
- Administration of subscriptions, plans, payments, billing methods and information, spending limits, invoice mgmt etc.
80
+
81
+
**Who can assign this role?**
82
+
83
+
- Organization Owner
84
+
85
+
**When this role first assigned?**
86
+
87
+
- Manually by Organization Owner
88
+
89
+
**How many instances of these roles?**
90
+
91
+
- Min: 0, Max: many
92
+
93
+
**Who can remove assignment of this role?**
94
+
95
+
- Organization Owner
96
+
97
+
{{% /card %}}
98
+
{{< /cardpane >}}
99
+
100
+
{{< alert title="Organization owners as entitlements" >}}
101
+
It's essential to understand that owners are not roles, but entitlements.
102
+
103
+
Organization owners carry the organization administrator role, and may be joined in their organization administration duties by any number of other users carrying the organization administrator role. However, the organization owner also has the administrative privilege to delete the organization.
104
+
105
+
The entitlement of "organization owner" is automatically bestowed to the creator of a organization. The individual user who created a given organization initially is therefore granted certain administrative privileges beyond that of other organization administrators. Specifically, organization owners retain the sole permission to delete the organization.
106
+
107
+
For more information, see [Organization](/cloud/identity/organizations).
108
+
{{< /alert >}}
109
+
110
+
## Team Roles
111
+
112
+
{{< cardpane >}}
113
+
{{% card header="Team Adminstrator" %}}
114
+
**What is the purpose of this role?**
115
+
116
+
- Administration of teams
117
+
118
+
**Who can assign and unassign this role?**
119
+
120
+
- Organization Administrator or Team owner
121
+
122
+
**When this role first assigned?**
123
+
124
+
- Creation of new team or User Account creation
125
+
- By default, the first Team Admin is owner (the team creator)
126
+
127
+
**How many instances of these roles?**
128
+
Min: 1, Max: many
129
+
130
+
{{% /card %}}
131
+
{{% card header="Team Manager" %}}
132
+
**What is the purpose of this role?**
133
+
134
+
- Administration of teams (without delete access)
135
+
136
+
**Who can assign and unassign this role?**
137
+
138
+
- Organization Administrators or Team Owner
139
+
140
+
**When this role first assigned?**
141
+
142
+
- Manually by Organization Administrator or Team Owner
143
+
144
+
**How many instances of these roles?**
145
+
146
+
- Min: 0, Max: many
38
147
{{% /card %}}
39
148
{{< /cardpane >}}
40
149
150
+
{{< alert title="Owners as entitlements, not roles" >}}
151
+
It's essential to understand that owners are not roles, but entitlements.
152
+
153
+
Team owners carry the team administrator role, and may be joined in their team administration duties by any number of other users carrying the team administrator role. However, the team owner also has the administrative privilege to delete the team.
154
+
155
+
The entitlement of "team owner" is automatically bestowed to the creator of a team. The individual user who created a given team initially is therefore granted certain administrative privileges beyond that of other team administrators. Specifically, team owners retain the sole permission to delete the team.
156
+
157
+
For more information, see [Teams](/cloud/identity/teams).
158
+
{{< /alert >}}
159
+
160
+
41
161
<!-- Text can be **bold**, _italic_, or ~~strikethrough~~. [Links](https://gohugo.io) should be blue with no underlines (unless hovered over).
42
162
43
163
There should be whitespace between paragraphs. Vape migas chillwave sriracha poutine try-hard distillery. Tattooed shabby chic small batch, pabst art party heirloom letterpress air plant pop-up. Sustainable chia skateboard art party banjo cardigan normcore affogato vexillologist quinoa meggings man bun master cleanse shoreditch readymade. Yuccie prism four dollar toast tbh cardigan iPhone, tumblr listicle live-edge VHS. Pug lyft normcore hot chicken biodiesel, actually keffiyeh thundercats photo booth pour-over twee fam food truck microdosing banh mi. Vice activated charcoal raclette unicorn live-edge post-ironic. Heirloom vexillologist coloring book, beard deep v letterpress echo park humblebrag tilde.
0 commit comments