Open Ask AI (⌘/Ctrl+I)

DX Cloud Identity and Access Management

In the Cockpit, roles define the access permissions a user has for various sections and actions. Each role is associated with specific capabilities, and users must have the required roles to interact with or view different parts of the system.

This page outlines the customer groups along with the roles and how they control access across features in the Cockpit.

In addition to Cockpit roles, descriptions for customer Rancher access are also described here.

Groups

For the Cockpit, there are groups to which you add users. These groups contain permissions through their assigned roles.

  • customer-admins: contains all roles below.
  • customer-devops
See roles (customer-devops)

For full details, see Roles.

  • cockpit-business
  • cockpit-developer
  • cockpit-devops
  • cockpit-support
  • logs-read
  • metrics-read
  • subscription-api-read
  • subscription-api-write
  • report-api-read
  • user-api-read
  • redirect-api-read
  • redirect-api-write
  • logs-api-audit-read
  • cluster-api-ingress-read
  • cluster-api-ingress-write
  • cluster-api-secret-read
  • cluster-api-secret-write
  • cluster-api-service-read
  • certificate-api-write
  • certificate-api-read
  • cdn-api-geofencing-read
  • cdn-api-geofencing-write
  • cdn-api-access-control-read
  • cdn-api-access-control-write
  • cdn-api-blocked-ips-read
  • cdn-api-blocked-ips-write
  • cdn-api-object-responses-read
  • cdn-api-object-responses-write
  • cdn-api-segmented-caching-read
  • cdn-api-segmented-caching-write
  • cdn-api-waiting-room-read
  • cdn-api-waiting-room-write
  • cdn-api-ttl-read
  • cdn-api-ttl-write
  • cdn-api-purge-all
  • cdn-api-purge-url
  • view-users
  • cluster-api-error-pages-read
  • cluster-api-error-pages-write
  • customer-operations
See roles (customer-operations)

For full details, see Roles.

  • cockpit-business
  • cockpit-developer
  • cockpit-devops
  • cockpit-support
  • logs-read
  • metrics-read
  • subscription-api-read
  • logs-api-audit-read
  • cdn-api-geofencing-read
  • cdn-api-geofencing-write
  • cdn-api-access-control-read
  • cdn-api-access-control-write
  • cdn-api-blocked-ips-read
  • cdn-api-blocked-ips-write
  • cdn-api-object-responses-read
  • cdn-api-object-responses-write
  • cdn-api-segmented-caching-read
  • cdn-api-segmented-caching-write
  • cdn-api-waiting-room-read
  • cdn-api-waiting-room-write
  • cdn-api-ttl-read
  • cdn-api-ttl-write
  • cdn-api-purge-all
  • cdn-api-purge-url
  • customer-project-owners
See roles (customer-project-owners)

For full details, see Roles.

  • cockpit-business
  • subscription-api-write
  • report-api-read

For Rancher access, there is only one group:

Roles

The table lists all possible roles for the Cockpit alongside the Cockpit sections you can access with each role and a short description of the access granted.

Key: Read = view-only access · Write = create, update, or delete

RoleCockpit sectionsAccess
admincentral-group-api-readAdmincentral GroupsRead: view groups via Cockpit
admincentral-group-api-writeAdmincentral GroupsWrite: manage groups via Cockpit
cdn-api-access-control-readCDNRead: CDN access control
cdn-api-access-control-writeCDNWrite: CDN access control
cdn-api-blocked-ips-readCDNRead: block IPs
cdn-api-blocked-ips-writeCDNWrite: block IPs
cdn-api-geofencing-readCDNRead: geofencing
cdn-api-geofencing-writeCDNWrite: geofencing
cdn-api-object-responses-readCDNRead: error responses
cdn-api-object-responses-writeCDNWrite: error responses
cdn-api-purge-allCDNWrite: purge all CDN cache
cdn-api-purge-urlCDNWrite: purge CDN cache for URL
cdn-api-segmented-caching-readCDNRead: segmented caching
cdn-api-segmented-caching-writeCDNWrite: segmented caching
cdn-api-ttl-readCDNRead: CDN TTL settings
cdn-api-ttl-writeCDNWrite: CDN TTL settings
cdn-api-waiting-room-readCDNRead: waiting room
cdn-api-waiting-room-writeCDNWrite: waiting room
certificate-api-readNetworkingRead: certificates
certificate-api-writeNetworkingWrite: certificates
cluster-api-ingress-readNetworkingRead: ingresses
cluster-api-ingress-writeNetworkingWrite: ingresses
cockpit-supportEnvironmentsPredefined set of roles associated with the support group
cockpit-businessCDN, ReportsPredefined set of roles associated with the business group
cockpit-developerNetworking, CDN, SecurityPredefined set of roles associated with the developer group
cockpit-devopsInfrastructure, Environments, Networking, CDN, Security, ReportsPredefined set of roles associated with the devops group
cockpit-user-managerAdminWrite: manage users
logs-api-audit-readAuditRead: audit logs
logs-readInfrastructure, LogsRead: events, all logs
redirect-api-readNetworkingRead: redirects
redirect-api-writeNetworkingWrite: redirects
report-api-readReportsRead: view reports
subscription-api-readCockpit header, AdminRead: subscription preferences, organisations
subscription-api-writeCockpit header, AdminWrite: subscription preferences, organisations
user-api-readAdminRead: users, groups
user-api-writeAdminWrite: users, groups
view-usersAdminRead: view users

Rancher roles

RoleDescription
rancher_projectadminAdmin access to Rancher configuration

To assign roles and manage users, see Admin.