Configuring role-based permissions
You can configure role-based access control (RBAC) for your Red Hat build of Kueue deployment to control which users can create specific Red Hat build of Kueue objects.
Cluster roles
The Red Hat build of Kueue Operator deploys kueue-batch-admin-role and kueue-batch-user-role cluster roles by default.
- kueue-batch-admin-role
This cluster role includes the permissions to manage cluster queues, local queues, workloads, and resource flavors.
- kueue-batch-user-role
This cluster role includes the permissions to manage jobs and to view local queues and workloads.
Configuring permissions for batch administrators
You can configure permissions for batch administrators by binding the kueue-batch-admin-role cluster role to a user or group of users.
Prerequisites
- The Red Hat build of Kueue Operator is installed on your cluster.
- You have cluster administrator permissions.
- You have installed the OpenShift CLI (
oc).
Procedure
- Create a
ClusterRoleBindingobject as a YAML file:Example ClusterRoleBinding objectapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: kueue-admins subjects: - kind: User name: admin@example.com apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: kueue-batch-admin-role apiGroup: rbac.authorization.k8s.iowhere:
metadata.nameSpecifies the name of the
ClusterRoleBindingobject.subjectsSpecifies the user or group of users you want to provide user permissions for.
roleRefSpecifies the
kueue-batch-admin-rolecluster role.
- Apply the
ClusterRoleBindingobject:terminal$ oc apply -f <filename>.yaml
Verification
- You can verify that the
ClusterRoleBindingobject was applied correctly by running the following command and verifying that the output contains the correct information for thekueue-batch-admin-rolecluster role:yaml$ oc describe clusterrolebinding.rbacExample output... Name: kueue-batch-admin-role Labels: app.kubernetes.io/name=kueue Annotations: <none> Role: Kind: ClusterRole Name: kueue-batch-admin-role Subjects: Kind Name Namespace ---- ---- --------- User admin@example.com admin-namespace ...
Configuring permissions for users
You can configure permissions for Red Hat build of Kueue users by binding the kueue-batch-user-role cluster role to a user or group of users.
Prerequisites
- The Red Hat build of Kueue Operator is installed on your cluster.
- You have cluster administrator permissions.
- You have installed the OpenShift CLI (
oc).
Procedure
- Create a
RoleBindingobject as a YAML file:Example ClusterRoleBinding objectapiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: kueue-users namespace: user-namespace subjects: - kind: Group name: team-a@example.com apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: kueue-batch-user-role apiGroup: rbac.authorization.k8s.iowhere:
metadata.nameSpecifies the name of the
RoleBindingobject.metadata.namespaceSpecifies the namespace the
RoleBindingobject applies to.subjectsSpecifies the user or group of users you want to provide user permissions for.
roleRefSpecifies the
kueue-batch-user-rolecluster role.
- Apply the
RoleBindingobject:terminal$ oc apply -f <filename>.yaml
Verification
- You can verify that the
RoleBindingobject was applied correctly by running the following command and verifying that the output contains the correct information for thekueue-batch-user-rolecluster role:yaml$ oc describe rolebinding.rbacExample output... Name: kueue-users Labels: app.kubernetes.io/name=kueue Annotations: <none> Role: Kind: ClusterRole Name: kueue-batch-user-role Subjects: Kind Name Namespace ---- ---- --------- Group team-a@example.com user-namespace ...