Role
Scenarios
A role is an identity type to which a set of permissions can be assigned. You can assign a role to a user to grant the user the permissions of that role. The bastion host system provides multiple default roles. You can also add custom roles.
Role Types
| Role Type | Role | Role Description | Role Restriction |
|---|---|---|---|
| Default system roles | DepartmentManager | This role is the department operation manager and manages the bastion host system. It has the permissions for user, resource, and policy management. |
|
| PolicyManager | This role is the user permission policy administrator. It manages host operation permissions. It has the permissions for configuration of the user management, resource management, and access policy management modules. | ||
| AuditManager | This role is the operation result audit administrator. It queries and manages system audit data. This role has the configuration permissions for real-time session, historical session, and system logs modules. | ||
| User | This role specifies common users and operators who can access the system. It has the permissions for operations for resources, such as host and application resources, and service ticket authorization management. | ||
| Custom role | - | You can customize the role name and permission scope as required. |
|
Notes and Constraints
Only the admin user has the permission to manage the Role module. This means only the admin user can create, edit, view, and delete roles.
Creating a Role
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Role to go to the role list page.
- On the displayed page, click New in the upper right corner of the page. In the displayed New Role dialog box, complete required parameters
Table 2 Parameters for creating a role Parameter
Description
Role
Enter a name for the role.
- The value of Role must be unique in a bastion host and cannot be changed after it is created.
- The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.
Managing Permission
Specify whether to enable management permission for the role. It is disabled by default. The management permission allows the role to view data of the current department and its lower-level departments.
- Enable: The role has management permissions and users with this role granted can view the data of their departments and lower-level departments. Users of this role can select a superior department when they add a resource or user. Only users with management permissions can grant ticket approval permission to a role. Otherwise, the approval permission will not take effect, even if it is enabled in 4.
- Disable: The role has no management permissions.
Role Manager Setting
Configure whether only the role manager can create users of this role or change other users to this role. This function is disabled by default.
- Enabled: You need to configure Role Manager. Only the user selected as the role manager can assign the current role to a user when creating or editing a user, as long as the selected user has permission to create or edit users.
You can select one or more roles as role managers and set yourself as the manager of your own role.
- Disabled: All users can select the current role when creating or editing a user, as long as they have permission to create or edit users.
Policy Delivery Target
Configure whether a policy can be applied to the current role. This function is enabled by default.
- Enabled: When you associate users with an access control rule, command control rule, or database control rule, users of this role are selectable.
- Disabled: When you associate users with an access control rule, command control rule, or database control rule, users of this role are not displayed and cannot be associated with the rule.
The rules for the policy delivery target to take effect are as follows:
- This configuration applies only when you select an associated user during policy creation or editing. It does not affect users already associated with the policy.
- This configuration does not apply when you associate a user group with a policy.
Remarks
(Optional) Provide a brief description of the role. A maximum of 128 characters can be entered.
- Click Next to go to the role configuration window.
Enable or disable the permission for each system module on the left. If the permission is enabled, you can select specific functions on the right of the corresponding system module. After the configuration, the role will have the permissions of the selected functions.
Figure 1 Configuring the permissions for a new role
- Click OK. You can then view the created role in the role list.
Viewing or Modifying the Basic Information and Permissions of a Role
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Role to go to the role list page.
- Query the target role.
Enter a keyword in the search box and search for a role by name.
- In the Operation column of the target role, click the role name or click Manage to go to the role details page.
- View or edit the basic information about the role.
- In the Basic Info area, view the detailed information about the role.
- In the right pane of the Basic Info area, click Edit. In the displayed dialog box, modify the basic information. For details, see Table 2.
- View or edit the permission scope of the role.
- In the Permissions area, view the system operation permissions of the role.
- In the Permissions area, click Edit on the right to modify the permissions of the role.
- Click Remove of a module to revoke permissions for the module of the role.
Restoring the Default Settings of a Default System Role
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Role to go to the role list page.
- In the Operation column of the target role, click Restore Default.
- In the displayed dialog box, click OK.
Deleting a Custom Role
Only the admin user can delete custom roles. Default system roles cannot be deleted.
If a role is deleted, all users with this role will immediately lose the permissions of the role. Exercise caution when performing this operation.
- Log in to your bastion host system.
- In the navigation pane on the left, choose User > Role to go to the role list page.
- Delete any role you no longer need.
- Deleting a role
- In the Operation column of the target role, click Delete.
- In the displayed dialog box, click OK.
- Batch deleting roles
- In the role list, select all target roles.
- Click Delete in the lower left corner.
- In the displayed dialog box, click OK.
- Deleting a role
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot