Skip to content

Commit 8635571

Browse files
authored
Merge pull request #65765 from bhardesty/osdocs-3159-dedicated-admin
OSDOCS-3159: Update dedicated-admin privs and add additional resources
2 parents f17e85b + 403451a commit 8635571

File tree

7 files changed

+37
-0
lines changed

7 files changed

+37
-0
lines changed

modules/rosa-sdpolicy-security.adoc

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ In addition to normal users, {product-title} provides access to an {product-titl
3030
- Can add and manage `NetworkPolicy` objects.
3131
- Are able to view information about specific nodes and PVs in the cluster, including scheduler information.
3232
- Can access the reserved `dedicated-admin` project on the cluster, which allows for the creation of service accounts with elevated privileges and also gives the ability to update default limits and quotas for projects on the cluster.
33+
- Can install Operators from OperatorHub and perform all verbs in all `*.operators.coreos.com` API groups.
3334

3435
[id="rosa-sdpolicy-cluster-admin-role_{context}"]
3536
== Cluster administration role

modules/sdpolicy-security.adoc

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ In addition to normal users, {product-title} provides access to an {product-titl
3030
* Can add and manage `NetworkPolicy` objects.
3131
* Are able to view information about specific nodes and PVs in the cluster, including scheduler information.
3232
* Can access the reserved `dedicated-admin` project on the cluster, which allows for the creation of service accounts with elevated privileges and also gives the ability to update default limits and quotas for projects on the cluster.
33+
* Can install Operators from OperatorHub (`\*` verbs in all `*.operators.coreos.com` API groups).
3334

3435
[id="cluster-admin-role_{context}"]
3536
== Cluster administration role

osd_getting_started/osd-getting-started.adoc

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,12 @@ include::modules/config-idp.adoc[leveloffset=+1]
4949
* For detailed steps to configure each of the supported identity provider types, see xref:../osd_install_access_delete_cluster/config-identity-providers.adoc#config-identity-providers[Configuring identity providers].
5050

5151
include::modules/osd-grant-admin-privileges.adoc[leveloffset=+1]
52+
53+
[role="_additional-resources"]
54+
.Additional resources
55+
56+
* xref:../osd_architecture/osd_policy/osd-service-definition.html#cluster-admin-user_osd-service-definition[Cluster administrator user]
57+
5258
include::modules/access-cluster.adoc[leveloffset=+1]
5359
include::modules/deploy-app.adoc[leveloffset=+1]
5460
include::modules/scaling-cluster.adoc[leveloffset=+1]

osd_install_access_delete_cluster/config-identity-providers.adoc

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,10 @@ include::modules/config-google-idp.adoc[leveloffset=+1]
1515
include::modules/config-ldap-idp.adoc[leveloffset=+1]
1616
include::modules/config-openid-idp.adoc[leveloffset=+1]
1717
include::modules/config-htpasswd-idp.adoc[leveloffset=+1]
18+
19+
[role="_additional-resources"]
20+
.Additional resources
21+
22+
* xref:../osd_architecture/osd_policy/osd-service-definition.html#cluster-admin-user_osd-service-definition[Cluster administrator user]
23+
1824
include::modules/access-cluster.adoc[leveloffset=+1]

rosa_getting_started/rosa-getting-started.adoc

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,13 @@ include::modules/rosa-getting-started-configure-an-idp.adoc[leveloffset=+2]
6161

6262
include::modules/rosa-getting-started-grant-user-access.adoc[leveloffset=+2]
6363
include::modules/rosa-getting-started-grant-admin-privileges.adoc[leveloffset=+2]
64+
65+
[role="_additional-resources"]
66+
.Additional resources
67+
68+
* xref:../rosa_architecture/rosa_policy_service_definition/rosa-service-definition.adoc#rosa-sdpolicy-cluster-admin-role_rosa-service-definition[Cluster administration role]
69+
* xref:../rosa_architecture/rosa_policy_service_definition/rosa-service-definition.html#rosa-sdpolicy-customer-admin-user_rosa-service-definition[Cluster administrator user]
70+
6471
include::modules/rosa-getting-started-access-cluster-web-console.adoc[leveloffset=+1]
6572
include::modules/deploy-app.adoc[leveloffset=+1]
6673
include::modules/rosa-getting-started-revoking-admin-privileges-and-user-access.adoc[leveloffset=+1]

rosa_getting_started/rosa-quickstart-guide-ui.adoc

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -118,6 +118,11 @@ include::modules/rosa-getting-started-grant-user-access.adoc[leveloffset=+2]
118118
[discrete]
119119
include::modules/rosa-getting-started-grant-admin-privileges.adoc[leveloffset=+2]
120120

121+
[role="_additional-resources"]
122+
.Additional resources
123+
124+
* xref:../rosa_architecture/rosa_policy_service_definition/rosa-service-definition.adoc#rosa-sdpolicy-cluster-admin-role_rosa-service-definition[Cluster administration role]
125+
* xref:../rosa_architecture/rosa_policy_service_definition/rosa-service-definition.html#rosa-sdpolicy-customer-admin-user_rosa-service-definition[Cluster administrator user]
121126

122127
//This content is pulled from rosa-getting-started-access-cluster-web-console.adoc
123128
include::modules/rosa-getting-started-access-cluster-web-console.adoc[leveloffset=+1]

rosa_install_access_delete_clusters/rosa-sts-accessing-cluster.adoc

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,19 @@ This document describes how to access a cluster and set up an IDP using the ROSA
1313
include::modules/rosa-accessing-your-cluster-quick.adoc[leveloffset=+1]
1414
include::modules/rosa-accessing-your-cluster.adoc[leveloffset=+1]
1515
include::modules/rosa-create-cluster-admins.adoc[leveloffset=+1]
16+
17+
[role="_additional-resources"]
18+
.Additional resources
19+
20+
* xref:../rosa_architecture/rosa_policy_service_definition/rosa-service-definition.adoc#rosa-sdpolicy-cluster-admin-role_rosa-service-definition[Cluster administration role]
21+
1622
include::modules/rosa-create-dedicated-cluster-admins.adoc[leveloffset=+1]
1723

24+
[role="_additional-resources"]
25+
.Additional resources
26+
27+
* xref:../rosa_architecture/rosa_policy_service_definition/rosa-service-definition.html#rosa-sdpolicy-customer-admin-user_rosa-service-definition[Cluster administrator user]
28+
1829
[role="_additional-resources"]
1930
== Additional resources
2031
* xref:../rosa_install_access_delete_clusters/rosa-sts-config-identity-providers.adoc#rosa-sts-config-identity-providers[Configuring identity providers using {cluster-manager-first} console]

0 commit comments

Comments
 (0)