Enabling user permissions to clone data volumes across namespaces
By default, users cannot clone resources between namespaces. To enable cloning, a user with the cluster-admin role must create and bind a cluster role that grants the required permissions.
To enable a user to clone a virtual machine to another namespace, a user with the cluster-admin role must create a new cluster role. Bind this cluster role to a user to enable them to clone virtual machines to the destination namespace.
Creating RBAC resources for cloning data volumes
You can create a new cluster role that enables permissions for all actions for the datavolumes resource.
Prerequisites
- You have installed the OpenShift CLI (
oc). - You must have cluster admin privileges.
If you are a non-admin user that is an administrator for both the source and target namespaces, you can create a Role instead of a ClusterRole where appropriate.
Procedure
-
Create a
ClusterRolemanifest:apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:name: <datavolume_cloner>rules:- apiGroups: ["cdi.kubevirt.io"]resources: ["datavolumes/source"]verbs: ["*"]# ...where:
<datavolume_cloner>- Specifies a unique name for the cluster role.
-
Create the cluster role in the cluster:
$ oc create -f <datavolume_cloner.yaml>where:
<datavolume_cloner.yaml>- Specifies the file name of the
ClusterRolemanifest created in the previous step.
-
Create a
RoleBindingmanifest that applies to both the source and destination namespaces and references the cluster role created in the previous step.apiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:name: <allow_clone_to_user>namespace: <source_namespace>subjects:- kind: ServiceAccountname: defaultnamespace: <destination_namespace>roleRef:kind: ClusterRolename: datavolume-clonerapiGroup: rbac.authorization.k8s.iometadata.namespecifies a unique name for the role binding.metadata.namespacespecifies the namespace for the source data volume.subjects.namespacespecifies the namespace to which the data volume is cloned.roleRef.namespecifies the name of the cluster role created in the previous step.
-
Create the role binding in the cluster:
$ oc create -f <datavolume_cloner.yaml>where:
<datavolume_cloner.yaml>- Specifies the file name of the
RoleBindingmanifest created in the previous step.