diff --git a/docs/sources/alerting/unified-alerting/rule-list.md b/docs/sources/alerting/unified-alerting/rule-list.md index 701d0f41ea3..dfdd96a01d7 100644 --- a/docs/sources/alerting/unified-alerting/rule-list.md +++ b/docs/sources/alerting/unified-alerting/rule-list.md @@ -39,11 +39,10 @@ A rule row shows the rule state, health, and summary annotation if the rule has ### Edit or delete rule - Grafana rules can only be edited or deleted by users with Edit permissions for the folder which contains the rule. Prometheus or Loki rules can be edited or deleted by users with Editor or Admin roles. To edit or delete a rule: 1. Expand this rule to reveal rule controls. -1. Click **Edit** to go to the rule editing form. Make changes following [instructions listed here]({{< relref "./create-alert-rule.md" >}}). +1. Click **Edit** to go to the rule editing form. Make changes following [instructions listed here]({{< relref "./create-grafana-managed-rule.md" >}}). 1. Click **Delete"** to delete a rule. diff --git a/docs/sources/enterprise/access-control/fine-grained-access-control-references.md b/docs/sources/enterprise/access-control/fine-grained-access-control-references.md new file mode 100644 index 00000000000..208b7296ff0 --- /dev/null +++ b/docs/sources/enterprise/access-control/fine-grained-access-control-references.md @@ -0,0 +1,31 @@ ++++ +title = "Fine-grained access control references" +description = "Refer to fine-grained access control references" +keywords = ["grafana", "fine-grained-access-control", "roles", "fixed-roles", "built-in-role-assignments", "permissions", "enterprise"] +weight = 110 ++++ + +# Fine-grained access control references +The reference information that follows complements conceptual information about [Roles]({{< relref "./roles.md" >}}). + +## Fine-grained access fixed roles + +Fixed roles | Permissions | Descriptions +--- | --- | --- +fixed:permissions:admin:read | roles:read
roles:list
roles.builtin:list | Allows to list and get available roles and built-in role assignments. +fixed:permissions:admin:edit | All permissions from `fixed:permissions:admin:read` and
roles:write
roles:delete
roles.builtin:add
roles.builtin:remove | Allows every read action and in addition allows to create, change and delete custom roles and create or remove built-in role assignments. +fixed:reporting:admin:read | reports:read
reports:send
reports.settings:read | Allows to read reports and report settings. +fixed:reporting:admin:edit | All permissions from `fixed:reporting:admin:read` and
reports.admin:write
reports:delete
reports.settings:write | Allows every read action for reports and in addition allows to administer reports. +fixed:users:admin:read | users.authtoken:list
users.quotas:list
users:read
users.teams:read | Allows to list and get users and related information. +fixed:users:admin:edit | All permissions from `fixed:users:admin:read` and
users.password:update
users:write
users:create
users:delete
users:enable
users:disable
users.permissions:update
users:logout
users.authtoken:update
users.quotas:update | Allows every read action for users and in addition allows to administer users. +fixed:users:org:read | org.users:read | Allows to get user organizations. +fixed:users:org:edit | All permissions from `fixed:users:org:read` and
org.users:add
org.users:remove
org.users.role:update | Allows every read action for user organizations and in addition allows to administer user organizations. +fixed:ldap:admin:read | ldap.user:read
ldap.status:read | Allows to read LDAP information and status. +fixed:ldap:admin:edit | All permissions from `fixed:ldap:admin:read` and
ldap.user:sync | Allows every read action for LDAP and in addition allows to administer LDAP. + +## Default built-in role assignments + +Built-in roles | Associated roles | Descriptions +--- | --- | --- +Grafana Admin | fixed:permissions:admin:edit
fixed:permissions:admin:read
fixed:reporting:admin:edit
fixed:reporting:admin:read
fixed:users:admin:edit
fixed:users:admin:read
fixed:users:org:edit
fixed:users:org:read
fixed:ldap:admin:edit
fixed:ldap:admin:read | Allows access to resources which [Grafana Server Admin]({{< relref "../../permissions/_index.md#grafana-server-admin-role" >}}) has permissions by default. +Admin | fixed:users:org:edit
fixed:users:org:read
fixed:reporting:admin:edit
fixed:reporting:admin:read | Allows access to resource which [Admin]({{< relref "../../permissions/organization_roles.md" >}}) has permissions by default. \ No newline at end of file diff --git a/docs/sources/enterprise/access-control/roles.md b/docs/sources/enterprise/access-control/roles.md index 3bf274a8dfe..9758957ef3c 100644 --- a/docs/sources/enterprise/access-control/roles.md +++ b/docs/sources/enterprise/access-control/roles.md @@ -28,18 +28,7 @@ There are few basic rules for fixed roles: - All fixed roles have a `fixed:` prefix. - You can’t change or delete a fixed role. -Role name | Permissions | Description ---- | --- | --- -fixed:permissions:admin:read | roles:read
roles:list
roles.builtin:list | Allows to list and get available roles and built-in role assignments. -fixed:permissions:admin:edit | All permissions from `fixed:permissions:admin:read` and
roles:write
roles:delete
roles.builtin:add
roles.builtin:remove | Allows every read action and in addition allows to create, change and delete custom roles and create or remove built-in role assignments. -fixed:reporting:admin:read | reports:read
reports:send
reports.settings:read | Allows to read reports and report settings. -fixed:reporting:admin:edit | All permissions from `fixed:reporting:admin:read` and
reports.admin:write
reports:delete
reports.settings:write | Allows every read action for reports and in addition allows to administer reports. -fixed:users:admin:read | users.authtoken:list
users.quotas:list
users:read
users.teams:read | Allows to list and get users and related information. -fixed:users:admin:edit | All permissions from `fixed:users:admin:read` and
users.password:update
users:write
users:create
users:delete
users:enable
users:disable
users.permissions:update
users:logout
users.authtoken:update
users.quotas:update | Allows every read action for users and in addition allows to administer users. -fixed:users:org:read | org.users:read | Allows to get user organizations. -fixed:users:org:edit | All permissions from `fixed:users:org:read` and
org.users:add
org.users:remove
org.users.role:update | Allows every read action for user organizations and in addition allows to administer user organizations. -fixed:ldap:admin:read | ldap.user:read
ldap.status:read | Allows to read LDAP information and status. -fixed:ldap:admin:edit | All permissions from `fixed:ldap:admin:read` and
ldap.user:sync | Allows every read action for LDAP and in addition allows to administer LDAP. +For more information, refer to [Fine-grained access control references]({{< relref "./fine-grained-access-control-references.md#fine-grained-access-fixed-roles" >}}). ## Custom roles @@ -47,28 +36,28 @@ Custom roles allow you to manage access to your users the way you want, by mappi To create, update or delete a custom role, you can use the [Fine-grained access control API]({{< relref "../../http_api/access_control.md" >}}) or [Grafana Provisioning]({{< relref "./provisioning.md" >}}). -##### Role name +### Role name A role's name is intended as a human friendly identifier for the role, helping administrators understand the purpose of a role. The name cannot be longer than 190 characters, and we recommend using ASCII characters. Role names must be unique within an organization. Roles with names prefixed by `fixed:` are fixed roles created by Grafana and cannot be created or modified by users. -##### Role version +### Role version The version of a role is a positive integer which defines the current version of the role. When updating a role, you can either omit the version field to increment the previous value by 1 or set a new version which must be strictly larger than the previous version for the update to succeed. -##### Permissions +### Permissions You manage access to Grafana resources by mapping [permissions]({{< relref "./permissions.md" >}}) to roles. You can create and assign roles without any permissions as placeholders. -##### Role UID +### Role UID Each custom role has a UID defined which is a unique identifier associated with the role allowing you to change or delete the role. You can either generate UID yourself, or let Grafana generate one for you. The same UID cannot be used for roles in different organizations within the same Grafana instance. -### Create, update and delete roles +## Create, update and delete roles You can create, update and delete custom roles by using the [Access Control HTTP API]({{< relref "../../http_api/access_control.md" >}}) or by using [Grafana Provisioning]({{< relref "./provisioning.md" >}}). @@ -79,23 +68,18 @@ Note that you won't be able to create, update or delete a custom role with permi ## Built-in role assignments -To control what your users can access or not, you can assign or unassign [Custom roles]({{< ref "#custom-roles" >}}) or [Fixed roles]({{< ref "#fixed-roles" >}}) to the existing [Organization roles]({{< relref "../../permissions/organization_roles.md" >}}) or to [Grafana Server Admin]({{< relref "../../permissions/_index.md#grafana-server-admin-role" >}}) role. +To control what your users can access or not, you can assign or unassign [Custom roles]({{< ref "#custom-roles" >}}) or [Fixed roles]({{< ref "#fixed-roles" >}}) to the existing [Organization roles]({{< relref "../../permissions/organization_roles.md" >}}) or to [Grafana Server Admin]({{< relref "../../permissions/_index.md#grafana-server-admin-role" >}}) role. These assignments are called built-in role assignments. During startup, Grafana will create default assignments for you. When you make any changes to the built-on role assignments, Grafana will take them into account and won’t overwrite during next start. -### Create and remove built-in role assignments +For more information, refer to [Fine-grained access control references]({{< relref "./fine-grained-access-control-references.md#default-built-in-role-assignments" >}}). -You can create or remove built-in role assignments using [Fine-grained access control API]({{< relref "../../http_api/access_control.md" >}}) or using [Grafana Provisioning]({{< relref "./provisioning">}}). +## Create and remove built-in role assignments + +You can create or remove built-in role assignments using [Fine-grained access control API]({{< relref "../../http_api/access_control.md" >}}) or using [Grafana Provisioning]({{< relref "./provisioning" >}}). ### Scope of assignments A built-in role assignment can be either _global_ or _organization local_. _Global_ assignments are not mapped to any specific organization and will be applied to all organizations, whereas _organization local_ assignments are only applied for that specific organization. -You can only create _organization local_ assignments for _organization local_ roles. - -### Default built-in role assignments - -Built-in role | Associated role | Description ---- | --- | --- -Grafana Admin | fixed:permissions:admin:edit
fixed:permissions:admin:read
fixed:reporting:admin:edit
fixed:reporting:admin:read
fixed:users:admin:edit
fixed:users:admin:read
fixed:users:org:edit
fixed:users:org:read
fixed:ldap:admin:edit
fixed:ldap:admin:read | Allows access to resources which [Grafana Server Admin]({{< relref "../../permissions/_index.md#grafana-server-admin-role" >}}) has permissions by default. -Admin | fixed:users:org:edit
fixed:users:org:read
fixed:reporting:admin:edit
fixed:reporting:admin:read | Allows access to resource which [Admin]({{< relref "../../permissions/organization_roles.md" >}}) has permissions by default. +You can only create _organization local_ assignments for _organization local_ roles. \ No newline at end of file