跳到主要内容
版本:v2.10

Global Resources1

Global Resources are non-namespaced resources provided by Rancher. Users who are cluster-owners/project-owners do not have access to several of these by default. For example principals and roletemplates.

The resources are documented here to support administrators creating and/or modifying custom sets of permissions with finding the minimum set of permissions needed for a particular task in the dashboard.

As an example, to use the cluster/project permissions pages of the dashboard requires permissions on principals to search/display a readable name for users, and on roleTemplates, to see a list of usable roleTemplates as well as to display a readable name for the role.

Please see the list below to determine what permissions you may need when creating a least-privilege user.

GroupResourcePurpose
auditlog.cattle.ioauditpoliciesSpecification of log filers, redactions, verbosity
catalog.cattle.ioclusterreposHelm chart repository location and credentials
management.cattle.ioauthconfigsConfiguration of external auth service providers
management.cattle.ioclustersRemote cluster management
management.cattle.iofeaturesFeature controlling rancher behaviour
management.cattle.ioglobalrolebindingsBinding of user/group to a global role
management.cattle.ioglobalrolesCustom role for global permissions (applied local and remote)
management.cattle.ionodedriversConfiguration of driver to provision clusters with a cloud service provider
management.cattle.ioroletemplatesTemplate for custom roles managing project- or cluster-specific permissions
management.cattle.iosettingsSetting controlling Rancher behaviour
management.cattle.iotokensRaw API key, old style.
management.cattle.iouserattributesAdditional information about a managed User
management.cattle.iousersUser known to and managed by Rancher
telemetry.cattle.iosecretrequestsRequest creation of a secret with arbitrary name, in any namespace