Configuring role-based permissions¶
You can configure role-based access control (RBAC) for your Red Hat build of Kueue deployment to control which users can create specific Red Hat build of Kueue objects.
Cluster roles¶
The Red Hat build of Kueue Operator deploys kueue-batch-admin-role and kueue-batch-user-role cluster roles by default.
- kueue-batch-admin-role
- This cluster role includes the permissions to manage cluster queues, local queues, workloads, and resource flavors.
- kueue-batch-user-role
- This cluster role includes the permissions to manage jobs and to view local queues and workloads.
Configuring permissions for batch administrators¶
You can configure permissions for batch administrators by binding the kueue-batch-admin-role cluster role to a user or group of users.
Prerequisites
- The Red Hat build of Kueue Operator is installed on your cluster.
- You have cluster administrator permissions.
- You have installed the OpenShift CLI (
oc).
Procedure
-
Create a
ClusterRoleBindingobject as a YAML file:Example ClusterRoleBinding objectapiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: kueue-admins subjects: - kind: User name: admin@example.com apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: kueue-batch-admin-role apiGroup: rbac.authorization.k8s.iowhere:
metadata.name- Specifies the name of the
ClusterRoleBindingobject. subjects- Specifies the user or group of users you want to provide user permissions for.
roleRef- Specifies the
kueue-batch-admin-rolecluster role.
-
Apply the
ClusterRoleBindingobject:
Verification
-
You can verify that the
ClusterRoleBindingobject was applied correctly by running the following command and verifying that the output contains the correct information for thekueue-batch-admin-rolecluster role:
Configuring permissions for users¶
You can configure permissions for Red Hat build of Kueue users by binding the kueue-batch-user-role cluster role to a user or group of users.
Prerequisites
- The Red Hat build of Kueue Operator is installed on your cluster.
- You have cluster administrator permissions.
- You have installed the OpenShift CLI (
oc).
Procedure
-
Create a
RoleBindingobject as a YAML file:Example ClusterRoleBinding objectapiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: kueue-users namespace: user-namespace subjects: - kind: Group name: team-a@example.com apiGroup: rbac.authorization.k8s.io roleRef: kind: ClusterRole name: kueue-batch-user-role apiGroup: rbac.authorization.k8s.iowhere:
metadata.name- Specifies the name of the
RoleBindingobject. metadata.namespace- Specifies the namespace the
RoleBindingobject applies to. subjects- Specifies the user or group of users you want to provide user permissions for.
roleRef- Specifies the
kueue-batch-user-rolecluster role.
-
Apply the
RoleBindingobject:
Verification
-
You can verify that the
RoleBindingobject was applied correctly by running the following command and verifying that the output contains the correct information for thekueue-batch-user-rolecluster role:
Additional resources