DX Cloud Identity and Access Management
In the Cockpit, roles define the access permissions a user has for various sections and actions. Each role is associated with specific capabilities, and users must have the required roles to interact with or view different parts of the system.
This page outlines the customer groups along with the roles and how they control access across features in the Cockpit.
In addition to Cockpit roles, descriptions for customer Rancher access are also described here.
Groups
For the Cockpit, there are groups to which you add users. These groups contain permissions through their assigned roles.
- customer-admins: contains all roles below.
- customer-devops
- customer-operations
- customer-project-owners
For Rancher access, there is only one group:
- customers: access through Rancher roles.
Roles
The table lists all possible roles for the Cockpit alongside the Cockpit sections you can access with each role and a short description of the access granted.
Key: Read = view-only access · Write = create, update, or delete
| Role | Cockpit sections | Access |
|---|---|---|
admincentral-group-api-read | Admincentral Groups | Read: view groups via Cockpit |
admincentral-group-api-write | Admincentral Groups | Write: manage groups via Cockpit |
cdn-api-access-control-read | CDN | Read: CDN access control |
cdn-api-access-control-write | CDN | Write: CDN access control |
cdn-api-blocked-ips-read | CDN | Read: block IPs |
cdn-api-blocked-ips-write | CDN | Write: block IPs |
cdn-api-geofencing-read | CDN | Read: geofencing |
cdn-api-geofencing-write | CDN | Write: geofencing |
cdn-api-object-responses-read | CDN | Read: error responses |
cdn-api-object-responses-write | CDN | Write: error responses |
cdn-api-purge-all | CDN | Write: purge all CDN cache |
cdn-api-purge-url | CDN | Write: purge CDN cache for URL |
cdn-api-segmented-caching-read | CDN | Read: segmented caching |
cdn-api-segmented-caching-write | CDN | Write: segmented caching |
cdn-api-ttl-read | CDN | Read: CDN TTL settings |
cdn-api-ttl-write | CDN | Write: CDN TTL settings |
cdn-api-waiting-room-read | CDN | Read: waiting room |
cdn-api-waiting-room-write | CDN | Write: waiting room |
certificate-api-read | Networking | Read: certificates |
certificate-api-write | Networking | Write: certificates |
cluster-api-ingress-read | Networking | Read: ingresses |
cluster-api-ingress-write | Networking | Write: ingresses |
cockpit-support | Environments | Predefined set of roles associated with the support group |
cockpit-business | CDN, Reports | Predefined set of roles associated with the business group |
cockpit-developer | Networking, CDN, Security | Predefined set of roles associated with the developer group |
cockpit-devops | Infrastructure, Environments, Networking, CDN, Security, Reports | Predefined set of roles associated with the devops group |
cockpit-user-manager | Admin | Write: manage users |
logs-api-audit-read | Audit | Read: audit logs |
logs-read | Infrastructure, Logs | Read: events, all logs |
redirect-api-read | Networking | Read: redirects |
redirect-api-write | Networking | Write: redirects |
report-api-read | Reports | Read: view reports |
subscription-api-read | Cockpit header, Admin | Read: subscription preferences, organisations |
subscription-api-write | Cockpit header, Admin | Write: subscription preferences, organisations |
user-api-read | Admin | Read: users, groups |
user-api-write | Admin | Write: users, groups |
view-users | Admin | Read: view users |
Rancher roles
| Role | Description |
|---|---|
rancher_projectadmin | Admin access to Rancher configuration |
To assign roles and manage users, see Admin.