Configuring role-based permissions
You can configure role-based access control (RBAC) for your Red Hat build of Kueue deployment to control which users can create specific Red Hat build of Kueue objects.
Cluster roles
The Red Hat build of Kueue Operator deploys kueue-batch-admin-role and kueue-batch-user-role cluster roles by default.
- kueue-batch-admin-role
- This cluster role includes the permissions to manage cluster queues, local queues, workloads, and resource flavors.
- kueue-batch-user-role
- This cluster role includes the permissions to manage jobs and to view local queues and workloads.
Configuring permissions for batch administrators
You can configure permissions for batch administrators by binding the kueue-batch-admin-role cluster role to a user or group of users.
Prerequisites
- The Red Hat build of Kueue Operator is installed on your cluster.
- You have cluster administrator permissions.
- You have installed the OpenShift CLI (
oc).
Procedure
-
Create a
ClusterRoleBindingobject as a YAML file:Example ClusterRoleBinding objectapiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:name: kueue-adminssubjects:- kind: Username: admin@example.comapiGroup: rbac.authorization.k8s.ioroleRef:kind: ClusterRolename: kueue-batch-admin-roleapiGroup: rbac.authorization.k8s.iowhere:
metadata.name- Specifies the name of the
ClusterRoleBindingobject. subjects- Specifies the user or group of users you want to provide user permissions for.
roleRef- Specifies the
kueue-batch-admin-rolecluster role.
-
Apply the
ClusterRoleBindingobject:$ oc apply -f <filename>.yaml
Verification
-
You can verify that the
ClusterRoleBindingobject was applied correctly by running the following command and verifying that the output contains the correct information for thekueue-batch-admin-rolecluster role:$ oc describe clusterrolebinding.rbacExample output...Name: kueue-batch-admin-roleLabels: app.kubernetes.io/name=kueueAnnotations: <none>Role:Kind: ClusterRoleName: kueue-batch-admin-roleSubjects:Kind Name Namespace---- ---- ---------User admin@example.com admin-namespace...
Configuring permissions for users
You can configure permissions for Red Hat build of Kueue users by binding the kueue-batch-user-role cluster role to a user or group of users.
Prerequisites
- The Red Hat build of Kueue Operator is installed on your cluster.
- You have cluster administrator permissions.
- You have installed the OpenShift CLI (
oc).
Procedure
-
Create a
RoleBindingobject as a YAML file:Example ClusterRoleBinding objectapiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:name: kueue-usersnamespace: user-namespacesubjects:- kind: Groupname: team-a@example.comapiGroup: rbac.authorization.k8s.ioroleRef:kind: ClusterRolename: kueue-batch-user-roleapiGroup: rbac.authorization.k8s.iowhere:
metadata.name- Specifies the name of the
RoleBindingobject. metadata.namespace- Specifies the namespace the
RoleBindingobject applies to. subjects- Specifies the user or group of users you want to provide user permissions for.
roleRef- Specifies the
kueue-batch-user-rolecluster role.
-
Apply the
RoleBindingobject:$ oc apply -f <filename>.yaml
Verification
-
You can verify that the
RoleBindingobject was applied correctly by running the following command and verifying that the output contains the correct information for thekueue-batch-user-rolecluster role:$ oc describe rolebinding.rbacExample output...Name: kueue-usersLabels: app.kubernetes.io/name=kueueAnnotations: <none>Role:Kind: ClusterRoleName: kueue-batch-user-roleSubjects:Kind Name Namespace---- ---- ---------Group team-a@example.com user-namespace...
Additional resources