What documentation can help set up RBAC based policies and admins
Applies to
- ONTAP 9
- role-based access control (RBAC)
- Export policies
Answer
1. Specify command directories and set appropriate access levels:
Example:
cluster::> securitylogin role create -role admin_role -cmddirname DEFAULT -access none -vserversvm1
cluster::> security login role create -role admin_role -cmddirname"vserver" -access all -vserver svm1
cluster::> security login role create -role admin_role -cmddirname"network" -access all -vserver svm1
cluster::> security login role create -role admin_role -cmddirname"system" -access all -vserver svm1
cluster::> security login role create -role admin_role -cmddirname"cluster" -access all -vserver svm1
- To restrict access to data, you may want todeny access to data-related command directories such as volume, file, and snapshot.
Example:
cluster::> securitylogin role create -role admin_role -cmddirname "volume" -access none-vserver svm1
cluster::> security login role create -role admin_role -cmddirname"file" -access none -vserver svm1
cluster::> security login role create -role admin_role -cmddirname"snapshot" -access none -vserver svm1
- After creating custom roles, create a user and assign the role to the user:
-
How to setup and configure access to specific export policy to user?
-
How to restrict the export policy commands to a specific group of users?
-
Can ONTAP RBAC limit vserver admin to certain export policy mods?
Ensure that the role and user are configured correctly by listing the roles and checking access levels:
Example:
cluster::> securitylogin role show -vserver svm1 -role admin_role
cluster::> security login show -vserver svm1 -user-or-group-name admin_user
Additional Information
- How to configure VSC to discover storage using SVM credentials
- To configure RBAC for VSC 9.6 and lower, see Recommended ONTAP roles when using VSC for VMware vSphere
- To configure RBAC for VSC 9.7 and later, see Configuring user roles and privileges
- How to configure RBAC access for ONTAP Tools using System Manager?
- Overview of RBAC security and ONTAP roles
- Worksheets for administrator authentication and RBAC configuration