Skip to main content
Version: v3.9.0

Role bindings

A RoleBinding grants one Role to subjects. Subjects are User, Group, or ServiceAccount.

roleRef and subjects sit at the document root. They are not fields of spec.

Fields are on RoleBinding fields.

A User name is the login name from the token (preferred_username, username, email, or sub). A Group name comes from resource_access[<client id>].roles, roles, or groups, lowercased, and should match an identity provider role name. admin, sre, developer, and viewer are the usual examples. A ServiceAccount subject uses the account metadata.name only. The application/name form belongs on describe and delete for the account itself.

agent-admin and microservice are Edgelet local API roles. A binding that grants them does not authorize /api/v3/*. Workload tokens use serviceAccount.roleRef on the microservice. See Roles.

Changing roles or roleBindings requires admin or a custom role. sre, developer, and viewer can get and list those resources. The verb table is on Roles. The operator note is RBAC.

Who may sign in is Embedded OIDC, External OIDC, and Identity and sign-in. This page is the grant after that sign-in.

Deploy​

potctl deploy -f rolebinding.yaml -n my-ecn
potctl get rolebindings -n my-ecn
potctl describe rolebinding alice-developer -n my-ecn
potctl delete rolebinding alice-developer -n my-ecn

deploy creates the binding when the name is missing. The same name replaces roleRef and subjects. There is no apply.

Deploy the Role before a binding that names it. Inside one file, the CLI deploys Role, then RoleBinding, then ServiceAccount.

After you change a binding, sign out and sign in again. The next token carries the new permissions.

metadata.namespace is the potctl namespace (-n).

describe rolebinding prints roleRef and subjects at the document root. delete rolebinding takes the binding name.

Example​

rolebinding.yaml
apiVersion: datasance.com/v3
kind: RoleBinding
metadata:
name: alice-developer
namespace: my-ecn
roleRef:
kind: Role
name: developer
subjects:
- kind: User

developer is a system role. See Access control. A ServiceAccount subject in a full stack is on that same page.

Console​

Open Access control, then Role Bindings. See Access control.

Group 3See anything wrong with the document? Help us improve it!