1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["10116"],{998634:function(e,s,n){n.r(s),n.d(s,{frontMatter:()=>i,toc:()=>c,default:()=>u,metadata:()=>t,assets:()=>o,contentTitle:()=>a});var t=JSON.parse('{"id":"clusters/cluster-management/cluster-rbac","title":"RBAC and Namespace Support","description":"Cluster Level RBAC and NS Support for Access Control","source":"@site/docs/docs-content/clusters/cluster-management/cluster-rbac.md","sourceDirName":"clusters/cluster-management","slug":"/clusters/cluster-management/cluster-rbac","permalink":"/clusters/cluster-management/cluster-rbac","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/clusters/cluster-management/cluster-rbac.md","tags":[{"inline":true,"label":"clusters","permalink":"/tags/clusters"},{"inline":true,"label":"cluster management","permalink":"/tags/cluster-management"}],"version":"current","lastUpdatedAt":1777826507000,"sidebarPosition":110,"frontMatter":{"sidebar_label":"RBAC and Namespace Support","title":"RBAC and Namespace Support","description":"Cluster Level RBAC and NS Support for Access Control","hide_table_of_contents":false,"sidebar_position":110,"tags":["clusters","cluster management"]},"sidebar":"docSidebar","previous":{"title":"Taints and Tolerations","permalink":"/clusters/cluster-management/taints"},"next":{"title":"Namespace Management","permalink":"/clusters/cluster-management/namespace-management"}}'),r=n(474848),l=n(884429);let i={sidebar_label:"RBAC and Namespace Support",title:"RBAC and Namespace Support",description:"Cluster Level RBAC and NS Support for Access Control",hide_table_of_contents:!1,sidebar_position:110,tags:["clusters","cluster management"]},a,o={},c=[{value:"Palette Roles and Kubernetes Roles",id:"palette-roles-and-kubernetes-roles",level:2},{value:"Create Role Bindings",id:"create-role-bindings",level:2},{value:"Prerequisites",id:"prerequisites",level:3},{value:"Enablement",id:"enablement",level:3},{value:"Validate",id:"validate",level:3},{value:"Cluster Role:",id:"cluster-role",level:4},{value:"Role",id:"role",level:4}];function d(e){let s={a:"a",admonition:"admonition",code:"code",em:"em",h2:"h2",h3:"h3",h4:"h4",img:"img",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,l.R)(),...e.components},{TabItem:t,Tabs:i,VersionedLink:a}=s;return t||h("TabItem",!0),i||h("Tabs",!0),a||h("VersionedLink",!0),(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(s.p,{children:[(0,r.jsx)(s.a,{href:"https://kubernetes.io/docs/reference/access-authn-authz/rbac/#rolebinding-and-clusterrolebinding",children:(0,r.jsx)(s.em,{children:"RoleBindings"})})," and\n",(0,r.jsx)(s.em,{children:"ClusterRoleBindings"})," are Role-Based Access Control (RBAC) concepts that allow granular control over cluster-wide\nresources. Palette provides you the ability to specify bindings to configure granular RBAC rules."]}),"\n",(0,r.jsxs)(s.p,{children:["You can configure namespaces and RBAC from within a cluster or from a ",(0,r.jsx)(s.a,{href:"/workspace/",children:"Palette Worksp
1ace"}),"\nthat contains a collection of like clusters that need to be managed as a group. If a host cluster is part of a Palette\nworkspace, then all roleBindings must occur at the namespace level."]}),"\n",(0,r.jsx)(s.p,{children:"As you review RBAC support, use the following definitions:"}),"\n",(0,r.jsxs)(s.ul,{children:["\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:[(0,r.jsx)(s.strong,{children:"Role"})," An entity that is assigned a set of access permissions within a namespace. Roles require the assignment of a\nKubernetes namespace."]}),"\n",(0,r.jsx)("br",{}),"\n",(0,r.jsx)(s.pre,{children:(0,r.jsx)(s.code,{className:"language-yaml",children:'apiVersion: rbac.authorization.k8s.io/v1\nkind: Role\nmetadata:\n namespace: default\n name: pod-reader\nrules:\n - apiGroups: [""]\n resources: ["pods"]\n verbs: ["get", "watch", "list"]\n'})}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:[(0,r.jsx)(s.strong,{children:"Cluster Role"})," An entity that is assigned a set of access permissions scoped to the cluster and all of its\nKubernetes namespaces. ClusterRoles do not have a namespace assigned."]}),"\n",(0,r.jsx)("br",{}),"\n",(0,r.jsx)(s.pre,{children:(0,r.jsx)(s.code,{className:"language-yaml",children:'apiVersion: rbac.authorization.k8s.io/v1\nkind: ClusterRole\nmetadata:\n name: secret-reader\nrules:\n - apiGroups: [""]\n resources: ["secrets"]\n verbs: ["get", "watch", "list"]\n'})}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:[(0,r.jsx)(s.strong,{children:"RoleBinding"})," associates a subject with a role. A subject can be a user, a group, or a\n",(0,r.jsx)(s.a,{href:"https://kubernetes.io/docs/concepts/security/service-accounts/",children:(0,r.jsx)(s.em,{children:"ServiceAccount"})}),". Role binding is used to grant\npermissions to a subject. Role and RoleBinding are used to scope a subject to a specific Kubernetes namespace."]}),"\n",(0,r.jsx)("br",{}),"\n",(0,r.jsx)(s.pre,{children:(0,r.jsx)(s.code,{className:"language-yaml",children:"apiVersion: rbac.authorization.k8s.io/v1\nkind: RoleBinding\nmetadata:\n name: read-pods\n namespace: default\nsubjects:\n - kind: User\n name: jane\n apiGroup: rbac.authorization.k8s.io\nroleRef:\n kind: Role\n name: pod-reader\n apiGroup: rbac.authorization.k8s.io\n"})}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:[(0,r.jsx)(s.strong,{children:"ClusterRoleBinding"})," associates a subject with a ClusterRole. A subject can be a user, a group, or a\n",(0,r.jsx)(s.a,{href:"https://kubernetes.io/docs/concepts/security/service-accounts/",children:(0,r.jsx)(s.em,{children:"ServiceAccount"})}),". A ClusterRoleBinding is used to\ngrant permissions to a subject. ClusterRole and ClusterRoleBinding are used to scope a subject's access to the cluster\nwhich includes all the Kubernetes namespaces inside the cluster."]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(s.p,{children:"There are many reasons why you may want to create roles and assign permissions to different users or groups. Below are a\nfew common scenarios."}),"\n",(0,r.jsxs)(s.ul,{children:["\n",(0,r.jsx)(s.li,{children:"Use Role and a RoleBinding to scope security to a single Kubernetes namespace."}),"\n",(0,r.jsx)(s.li,{children:"Use Role and a RoleBinding to scope security to several Kubernetes namespaces."}),"\n",(0,r.jsx)(s.li,{children:"Use ClusterRole and ClusterRoleBinding to scope security to all namespaces."}),"\n"]}),"\n",(0,r.jsx)("br",{}),"\n",(0,r.jsx)(s.admonition,{type:"warning",children:(0,r.jsx)(s.p,{children:"Palette does not provide a way for roles to be configured natively through its platform. You can create roles by using a\nmanifest layer in the cluster profile. RBAC management only allows you to specify role bindings."})}),"\n",(0,r.jsx)(s.p,{children:"Use the steps below to create a RoleBinding or ClusterRoleBinding for your host clusters."}),"\n",(0,r.jsx)("br",{}),"\n",(0,r.jsx)(s.h2,{id:"palette-roles-and-kubernetes-roles",children:"Palette Roles and Kubernetes Roles"}),"\n",(0,r.jsxs)(s.p,{children:["Palette offers a set of ",(0,r.jsx)(s.a,{href:"/user-management/palette-rbac/",children:"default roles"})," you can assign to your\nusers. The Palette roles are only in scope at the platform level. This means you can manage the permissions for users'\nactions in Palette, such as creating or deleting cluster
1s, creating projects, creating users, and more."]}),"\n",(0,r.jsxs)(s.p,{children:["The Kubernetes roles are used to control the actions users are allowed to do inside the cluster. For example, a user in\nPalette could have the ",(0,r.jsx)(s.em,{children:"Cluster Profile Viewer"})," role, which grants them the ability to view cluster profiles for a\nspecific project. In all the clusters in this project, the user could be assigned a role binding to a custom role that\ngrants them administrative access in all the clusters."]}),"\n",(0,r.jsx)(s.p,{children:"In summary, using Palette roles allows you to control what actions users can do in Palette. Use Kubernetes roles to\ncontrol users' actions inside a host cluster."}),"\n",(0,r.jsx)("br",{}),"\n",(0,r.jsx)(s.admonition,{type:"warning",children:(0,r.jsx)(s.p,{children:"Palette roles do not automatically map to a Kubernetes role. You must create a role binding for a specific user or group\nof users."})}),"\n",(0,r.jsx)(s.h2,{id:"create-role-bindings",children:"Create Role Bindings"}),"\n",(0,r.jsx)(s.h3,{id:"prerequisites",children:"Prerequisites"}),"\n",(0,r.jsxs)(s.p,{children:["To create a role binding the role must exist inside the host cluster. You can use any of the\n",(0,r.jsx)(s.a,{href:"https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles",children:"default cluster roles"})," provided by\nKubernetes. The alternative to default cluster roles is to create a role by using a manifest in the cluster profile."]}),"\n",(0,r.jsxs)(s.p,{children:["If you have OpenID Connect (OIDC) configured at the Kubernetes layer of your cluster profile, you can create a role\nbinding that maps individual users or groups assigned within the OIDC provider's configuration to a role. To learn more,\nreview ",(0,r.jsx)(a,{text:"Use RBAC with OIDC",url:"/integrations/packs/?pack=kubernetes"}),"."]}),"\n",(0,r.jsx)(s.h3,{id:"enablement",children:"Enablement"}),"\n",(0,r.jsx)(s.p,{children:"You can create role bindings during the cluster creation process or after the host cluster is deployed."}),"\n",(0,r.jsxs)(s.p,{children:["For a new cluster, you can modify the cluster settings at the end of the cluster creation process. RBAC is one of the\ncluster settings you can modify. Select ",(0,r.jsx)(s.strong,{children:"RBAC"})," from the left ",(0,r.jsx)(s.strong,{children:"Settings Menu"}),"."]}),"\n",(0,r.jsx)(s.p,{children:(0,r.jsx)(s.img,{alt:"A view of the cluster settings page when creating a cluster",src:n(344454).A+"",width:"1671",height:"1074"})}),"\n",(0,r.jsxs)(s.p,{children:["To create or modify a role binding for an active cluster. Navigate to the cluster details page and click on\n",(0,r.jsx)(s.strong,{children:"Settings"}),". Select ",(0,r.jsx)(s.strong,{children:"RBAC"})," from the left ",(0,r.jsx)(s.strong,{children:"Settings Menu"}),"."]}),"\n",(0,r.jsx)(s.p,{children:(0,r.jsx)(s.img,{alt:"A view of the cluster settings page for an active cluster",src:n(938652).A+"",width:"1729",height:"1089"})}),"\n",(0,r.jsx)(s.p,{children:"The RBAC settings view contains two tabs:"}),"\n",(0,r.jsxs)(s.ul,{children:["\n",(0,r.jsxs)(s.li,{children:[(0,r.jsx)(s.strong,{children:"Cluster"}),": Use this tab to create a ClusterRoleBinding."]}),"\n",(0,r.jsxs)(s.li,{children:[(0,r.jsx)(s.strong,{children:"Namespaces"}),": Use this tab to create a RoleBinding within Kubernetes namespaces."]}),"\n"]}),"\n",(0,r.jsx)(s.p,{children:"Select the tab for your specific role scope to learn how to create the appropriate role binding."}),"\n",(0,r.jsxs)(i,{queryString:"role",children:[(0,r.jsxs)(t,{label:"Assign a Cluster Role",value:"clusterRoleBinding",children:[(0,r.jsxs)(s.ol,{children:["\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["From the cluster settings view, select the ",(0,r.jsx)(s.strong,{children:"RBAC"})," tab."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Click on ",(0,r.jsx)(s.strong,{children:"Add New Binding"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsx)(s.p,{children:"Fill out the following details:"}),"\n"]}),"\n"]}),(0,r.jsxs)(s.ul,{children:["\n",(0,r.jsx)(s.li,{children:"Role Name: Define a custom role name to identify the cluster role."}),"\n",(0,r.jsx)(s.li,{children:"Subjects: Subjects are a group of users, services, or teams using the Kubernetes API. If you are using Palette as your\nIDP, you can use the Palette user's registration email address to identify the user."}),"\n",(0,r.jsx)(s.li,{children:"Subject Name: Custom name to identify a subject."}),"\n"]}),(0,r.jsx)(s.admonition,{type:"info",children:(0,r.jsx)(s.p,{children:"In Kubernetes, a role binding connects a user or group with a set of permissions called a Role. The Role can be in the\nsame namespace as the RoleBinding. If you want to give a role access to all the namespaces in your cluster, use a\nClusterRoleBinding."})}),(0,r.jsxs)(s.ol,{start:"4",children:["\n",(0,r.jsxs)(s.li,{children:["Click on ",(0,r.jsx)(s.strong,{children:"Confirm"})," to save your changes."]}),"\n"]}),(0,r.jsx)(s.p,{children:"A ClusterRoleBinding will be created in your host cluster. Keep in mind that you can assign multiple subjects to a\nClusterRoleBinding."})]}),(0,r.jsxs)(t,{label:"Assign a Namespace Role",value:"roleBinding",children:[(0,r.jsxs)(s.ol,{children:["\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["From the cluster settings view, select the ",(0,r.jsx)(s.strong,{children:"RBAC"})," tab."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Click on ",(0,r.jsx)(s.strong,{children:"Add New Binding"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Add the namespace name or provide a regular expression to automatically apply the following settings to other\nnamespaces in the future. Example: ",(0,r.jsx)(s.code,{children:"/^web-app/"}),". Click on ",(0,r.jsx)(s.strong,{children:"Add To List"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsx)(s.p,{children:"Allocate resources to the selected namespace. You can allocate the maximum CPU and Memory the role is allowed to\nconsume from the listed namespaces."}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Click on ",(0,r.jsx)(s.strong,{children:"Add New Binding"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsx)(s.p,{children:"Fill out the following details:"}),"\n"]}),"\n"]}),(0,r.jsxs)(s.ul,{children:["\n",(0,r.jsx)(s.li,{children:"Namespace: Select the namespace."}),"\n",(0,r.jsx)(s.li,{children:"Role Type: The type of role. You can specify either a role or a cluster role."}),"\n",(0,r.jsx)(s.li,{children:"Role Name: Define a custom role name to identify the cluster role."}),"\n",(0,r.jsx)(s.li,{children:"Subjects: Subjects are a group of users, services, or teams using the Kubernetes API."}),"\n",(0,r.jsx)(s.li,{children:"Subject Name: Custom name to identify a subject."}),"\n"]}),(0,r.jsx)(s.admonition,{type:"info",children:(0,r.jsx)(s.p,{children:"In Kubernetes, a role binding connects a user or group with a set of permissions called a Role. The Role can be in the\nsame namespace as the RoleBinding. If you want to give a role access to all the namespaces in your cluster, use a\nClusterRoleBinding."})}),(0,r.jsx)(s.p,{children:"A role binding will be created in the listed namespaces. Keep in mind that you can assign multiple subjects to a\nRoleBinding or ClusterRoleBinding."})]})]}),"\n",(0,r.jsx)(s.h3,{id:"validate",children:"Validate"}),"\n",(0,r.jsxs)(s.ol,{children:["\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Log in to ",(0,r.jsx)(s.a,{href:"https://console.spectrocloud.com",children:"Palette"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Navigate to the left ",(0,r.jsx)(s.strong,{children:"Main Menu"}
1)," and select ",(0,r.jsx)(s.strong,{children:"Clusters"}),"."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsx)(s.p,{children:"Select the cluster you created the role binding in to view its details page."}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsxs)(s.p,{children:["Download the ",(0,r.jsx)(s.strong,{children:"kubeconfig"})," file for the cluster or use the web shell to access the host cluster."]}),"\n"]}),"\n",(0,r.jsxs)(s.li,{children:["\n",(0,r.jsx)(s.p,{children:"Use the following commands to review details about the role and to ensure the role binding was successful."}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(s.h4,{id:"cluster-role",children:"Cluster Role:"}),"\n",(0,r.jsx)(s.pre,{children:(0,r.jsx)(s.code,{className:"language-shell",children:"kubectl get clusterrole <yourRoleNameHere> --output yaml\n"})}),"\n",(0,r.jsx)(s.h4,{id:"role",children:"Role"}),"\n",(0,r.jsx)(s.pre,{children:(0,r.jsx)(s.code,{className:"language-shell",children:"kubectl get role <yourRoleNameHere> --namespace <namespace> --show-kind --export\n"})})]})}function u(e={}){let{wrapper:s}={...(0,l.R)(),...e.components};return s?(0,r.jsx)(s,{...e,children:(0,r.jsx)(d,{...e})}):d(e)}function h(e,s){throw Error("Expected "+(s?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}},344454:function(e,s,n){n.d(s,{A:()=>t});let t=n.p+"assets/images/clusters_cluster-management_cluster-rbac_cluster-creation-settings-88af9533968c21480c0653f0851b0563.webp"},938652:function(e,s,n){n.d(s,{A:()=>t});let t=n.p+"assets/images/clusters_cluster-management_cluster-rbac_cluster-settings-03188f2113bc8cb9027e36d3ee374871.webp"},884429:function(e,s,n){n.d(s,{R:()=>i,x:()=>a});var t=n(296540);let r={},l=t.createContext(r);function i(e){let s=t.useContext(l);return t.useMemo(function(){return"function"==typeof e?e(s):{...s,...e}},[s,e])}function a(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:i(e.components),t.createElement(l.Provider,{value:s},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.