Skip to main content
Version: v3.9.0

Access control

Access Control is always in the sidebar. It is role-based access for the Controller API, plus the NATS rules that applications and microservices reference.

PageAddressPage headingDeep link
Roles/#/access-control/rolesRolesroleName
Role Bindings/#/access-control/rolebindingsRole BindingsroleBindingName
Service Accounts/#/access-control/serviceaccountsService AccountsserviceAccountName
NATS Account Rules/#/access-control/nats-account-rulesNATS Account RulesruleName
NATS User Rules/#/access-control/nats-user-rulesNATS User RulesruleName

Every page has Search and the YAML dropzone. Click the name to open the detail panel. Roles, role bindings, and service accounts refresh the open panel. The two NATS rule panels show the row you clicked and do not poll.

Application NATS Config links to an account rule. Microservice NATS Config links to a user rule. Both use ruleName. Issued credentials are on Message bus.

Roles​

Roles

A role is a set of API rules: which resource types, and which verbs, a subject may use. How a role is declared: Roles.

ColumnWhat it shows
NameRole name. Click to open the detail panel.
RulesHow many rules the role contains

Loading overlay: Fetching Role Details.

Role detail panel​

Role detail

Title is the role name, or Role Details.

IconNameWhat happens
EditRole YAML in the bottom drawer. Save updates the role.
DeleteDeleting Role plus the name. The message warns about role bindings that still point at it.
CloseCloses the panel.

Role Details: Name.

Rules: each rule shows API Groups, Resources, Verbs, and Resource Names. If the role has no rules, the section says No rules defined.

Role Bindings​

Role bindings

A role binding grants a role to subjects (users, groups, or service accounts). How a binding is declared: Role bindings.

ColumnWhat it shows
NameBinding name. Click to open the detail panel.
RoleroleRef name
SubjectsHow many subjects are bound

Loading overlay: Fetching RoleBinding Details.

Role binding detail panel​

Title is the binding name.

IconNameWhat happens
EditRole binding YAML.
DeleteDeleting RoleBinding plus the name.
CloseCloses the panel.

RoleBinding Details: Name.

Role Reference: Kind, Name, API Group.

Subjects: one badge per subject.

Service Accounts​

Service accounts

A service account belongs to an application and points at a role. Microservices can mount that identity. The mount itself shows up on the microservice as a volume of type serviceAccount, which the console does not let you delete. How a service account is declared: Service accounts.

ColumnWhat it shows
ApplicationApplication name. Click to open the detail panel.
NameService account name. Click to open the same panel.
Role ReferenceRole the account uses

The deep link needs the service account name. The list row supplies the application.

Loading overlay: Fetching ServiceAccount Details.

Service account detail panel​

Title is the application, a slash, and the name, or ServiceAccount Details.

IconNameWhat happens
EditService account YAML.
DeleteDeleting ServiceAccount plus the name.
CloseCloses the panel.

Fields: Application, Name, then Role Reference (kind, name, API group) or No role reference defined.

NATS Account Rules​

NATS account rules

An account rule is the policy applied when the platform ensures a NATS account for an application. Applications link to a rule by name from their NATS config. How a rule is declared: NATS account rules.

ColumnWhat it shows
NameRule name. Click to open the detail panel.
DescriptionDescription
SystemYes or No

Loading overlay on the list: Fetching NATS Account Rules. The panel uses the row you clicked. It does not fetch a second record and it does not poll.

Account rule detail panel​

IconNameWhat happens
EditRule YAML.
DeleteDeleting NATS Account Rule plus the name. Hidden for the built-in rules below.
CloseCloses the panel.

Fields: Name, System, Description, and Rule Spec (the rule JSON).

Delete is unavailable for:

  • default-system-account-rule
  • default-application-account-rule

NATS User Rules​

NATS user rules

Same layout as account rules, for the policy applied to NATS users and MQTT bearers. Microservice NATS config links here. How a rule is declared: NATS user rules.

ColumnWhat it shows
NameRule name. Click to open the detail panel.
DescriptionDescription
SystemYes or No

User rule detail panel​

Icons match account rules: Edit, Delete (hidden for built-in rules), Close.

Fields: Name, System, Description, Rule Spec.

Delete is unavailable for:

  • default-microservice-user-rule
  • default-mqtt-bearer-user-rule

And for the two default account-rule names if they appear in this list. The console treats that whole set as reserved.

Group 3See anything wrong with the document? Help us improve it!