diff --git a/conf/provisioning/access-control/sample.yaml b/conf/provisioning/access-control/sample.yaml index a7a038e7267..5fe577bf996 100644 --- a/conf/provisioning/access-control/sample.yaml +++ b/conf/provisioning/access-control/sample.yaml @@ -3,37 +3,42 @@ # # list of default built-in role assignments that should be removed # removeDefaultAssignments: -# # , must be one of the Organization roles (`Viewer`, `Editor`, `Admin`) or `Grafana Admin` +# # , must be one of the Organization roles (`Viewer`, `Editor`, `Admin`) or `Grafana Admin` # - builtInRole: "Grafana Admin" -# # , must be one of the existing predefined roles -# predefinedRole: "grafana:roles:permissions:admin" +# # , must be one of the existing fixed roles +# fixedRole: "fixed:permissions:admin" # # list of default built-in role assignments that should be added back # addDefaultAssignments: -# # , must be one of the Organization roles (`Viewer`, `Editor`, `Admin`) or `Grafana Admin` +# # , must be one of the Organization roles (`Viewer`, `Editor`, `Admin`) or `Grafana Admin` # - builtInRole: "Admin" -# # , must be one of the existing predefined roles -# predefinedRole: "grafana:roles:reporting:admin:read" +# # , must be one of the existing fixed roles +# fixedRole: "fixed:reporting:admin:read" # # list of roles that should be deleted # deleteRoles: # # name of the role you want to create. Required if no uid is set -# - name: "custom:roles:reporting:admin:edit" +# - name: "custom:reports:editor" # # uid of the role. Required if no name -# uid: customrolesreportingadminedit +# uid: "customreportseditor1" # # org id. will default to Grafana's default if not specified # orgId: 1 # # force deletion revoking all grants of the role # force: true +# - name: "custom:global:reports:reader" +# uid: "customglobalreportsreader1" +# # overwrite org id and removes a global role +# global: true +# force: true # # list of roles to insert/update depending on what is available in the database # roles: # # name of the role you want to create. Required -# - name: custom:roles:users:editor +# - name: "custom:users:editor" # # uid of the role. Has to be unique for all orgs. -# uid: customrolesuserseditor +# uid: customuserseditor1 # # description of the role, informative purpose only. -# description: "Role to allow users to create/read/write users" +# description: "Role for our custom user editors" # # version of the role, Grafana will update the role when increased # version: 2 # # org id. will default to Grafana's default if not specified @@ -51,6 +56,21 @@ # # list of builtIn roles the role should be assigned to # builtInRoles: # # name of the builtin role you want to assign the role to -# - name: "Admin" +# - name: "Editor" # # org id. will default to the role org id -# orgId: 1 +# orgId: 1 +# - name: "custom:global:users:reader" +# uid: "customglobalusersreader1" +# description: "Global Role for custom user readers" +# version: 1 +# # overwrite org id and creates a global role +# global: true +# permissions: +# - action: "users:read" +# scope: "users:*" +# builtInRoles: +# - name: "Viewer" +# orgId: 1 +# - name: "Editor" +# # overwrite org id and assign role globally +# global: true