Skip to main content
Version: v3.9.0

Roles

A Role is a list of rules in the Controller for one namespace. Each rule names an API group, resources, and verbs.

rules sits at the document root. It is not a field of spec.

Fields are on Role fields. A Role does not grant access by itself. A RoleBinding grants it to a User, Group, or ServiceAccount. A workload identity is a ServiceAccount.

This is Controller RBAC. A Kubernetes Role from the operator install is a different object. See Kubernetes.

The built-in admin role cannot be modified or deleted. The other system roles are on Access control.

Deploy​

potctl deploy -f role.yaml -n my-ecn
potctl get roles -n my-ecn
potctl describe role app-worker -n my-ecn
potctl delete role app-worker -n my-ecn

deploy creates the Role when the name is missing. The same name replaces the rules. There is no apply.

Deploy the Role before a RoleBinding that names it.

metadata.name is the role name used in roleRef.name. metadata.namespace is the potctl namespace (-n).

describe role prints rules at the document root. delete role takes the name. admin cannot be deleted.

Example​

role.yaml
apiVersion: datasance.com/v3
kind: Role
metadata:
name: app-worker
namespace: my-ecn
rules:
- apiGroups: [""]
resources:
- microservices
verbs:
- get
- list

Name the resources and verbs that caller needs. admin already allows every resource and every verb.

Resources​

admin is every resource and every verb, so it is not a column here. * covers get, list, create, update, patch, and delete. none means the role does not include that resource.

These roles authorize users and groups on /api/v3/*. A custom role uses the same resource names. Routes are the Controller API. The operator note is RBAC.

ResourceSREDeveloperViewerNotes
microservices*get, list, create, update, patch, deleteget, list
systemMicroservices*get, listget, list
fogs*get, listget, listPOST …/reconcile is patch.
applications*get, list, create, update, patch, deleteget, list
systemApplications*get, listget, list
applicationTemplates*get, list, create, update, patch, deleteget, list
microserviceTemplates*get, list, create, update, patch, deleteget, list
services*get, list, create, update, patch, deleteget, listPOST …/reconcile is patch.
router*get, listget, list
networkTopology*get, listget, listGET only under /api/v3/network-topology/.
cluster*get, listget, listHA controllers.
natsOperator, natsBootstrap, natsHubget, listget, listget, listRead-only. Account, user, and rule changes use the rows below.
natsAccounts, natsUsers, natsAccountRules, natsUserRules*get, list, create, update, patch, deleteget, listMQTT bearer create and delete are on natsUsers. Account rules, User rules.
catalog, registries*get, list, create, update, patch, deleteget, list
secrets, configMaps, volumeMounts, models, knowledge, runtimeClasses*get, list, create, update, patch, deleteget, listLink on volume mounts, models, knowledge, and runtime classes is patch.
tunnels*get, listnone
certificates, capabilities*get, list, create, update, patch, deleteget, list
execSessions, logs*get, list, create, update, patch, deletenone
systemExecSessions, systemLogs*get, listnone
events*nonenone
users*get, listget, listProfile is get. Password change and MFA are patch and delete. Login, refresh, logout, and OAuth routes use an empty verb list.
authUsers, authGroups*get, listget, listEmbedded identity admin.
config*get, listget, list
controller*get, list, create, update, patch, deleteget, list/live, /status, and /architectures/ are public. The role check is skipped.
roles, roleBindingsget, listget, listget, listChanges require admin or a custom role.
serviceAccounts*get, list, create, update, patch, deleteget, listController API for the object. Workload tokens use the Edgelet roles below.
authAdminnonenonenoneadmin only. JWKS rotate and auth migration.
agentnonenonenoneFog token on /api/v3/agent/*. Not user RBAC.

Edgelet service account roles​

agent-admin and microservice authorize the Edgelet local API on the node. They do not authorize /api/v3/*.

A microservice sets serviceAccount.roleRef to a Role in API group edgelet.iofog.org/v1. The Controller returns those rules with the workload. The Edgelet node mints the token the container presents to the local API.

RoleAPI groupResourceVerbsWhat the workload can call
agent-adminedgelet.iofog.org/v1**Every local API
microserviceedgelet.iofog.org/v1microservices/config/selfgetThis workload's own config
microserviceedgelet.iofog.org/v1auth/whoamigetIdentity of the calling workload
microserviceedgelet.iofog.org/v1system/gpsgetNode GPS
microserviceedgelet.iofog.org/v1microservices/control/selfgetThis workload's own control endpoint

microservice is the default self-service role. agent-admin is the unrestricted local API role. A custom Role in edgelet.iofog.org/v1 is delivered the same way when serviceAccount.roleRef names it.

Console​

Open Access control, then Roles. See Access control.

Group 3See anything wrong with the document? Help us improve it!