mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-26 04:58:07 +00:00
Merge pull request #3359 from catherineluse/configure-catalogs
Document privilege escalation through the configure catalogs permission
This commit is contained in:
@@ -9,6 +9,8 @@ Within Rancher, _roles_ determine what actions a user can make within a cluster
|
|||||||
|
|
||||||
Note that _roles_ are different from _permissions_, which determine what clusters and projects you can access.
|
Note that _roles_ are different from _permissions_, which determine what clusters and projects you can access.
|
||||||
|
|
||||||
|
> It is possible for a custom role to enable privilege escalation. For details, see [this section.](#privilege-escalation)
|
||||||
|
|
||||||
This section covers the following topics:
|
This section covers the following topics:
|
||||||
|
|
||||||
- [Prerequisites](#prerequisites)
|
- [Prerequisites](#prerequisites)
|
||||||
@@ -16,15 +18,16 @@ This section covers the following topics:
|
|||||||
- [Creating a custom global role](#creating-a-custom-global-role)
|
- [Creating a custom global role](#creating-a-custom-global-role)
|
||||||
- [Deleting a custom global role](#deleting-a-custom-global-role)
|
- [Deleting a custom global role](#deleting-a-custom-global-role)
|
||||||
- [Assigning a custom global role to a group](#assigning-a-custom-global-role-to-a-group)
|
- [Assigning a custom global role to a group](#assigning-a-custom-global-role-to-a-group)
|
||||||
|
- [Privilege escalation](#privilege-escalation)
|
||||||
|
|
||||||
## Prerequisites
|
# Prerequisites
|
||||||
|
|
||||||
To complete the tasks on this page, one of the following permissions are required:
|
To complete the tasks on this page, one of the following permissions are required:
|
||||||
|
|
||||||
- [Administrator Global Permissions]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/global-permissions/).
|
- [Administrator Global Permissions]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/global-permissions/).
|
||||||
- [Custom Global Permissions]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/global-permissions/#custom-global-permissions) with the [Manage Roles]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/global-permissions/) role assigned.
|
- [Custom Global Permissions]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/global-permissions/#custom-global-permissions) with the [Manage Roles]({{<baseurl>}}/rancher/v2.5/en/admin-settings/rbac/global-permissions/) role assigned.
|
||||||
|
|
||||||
## Creating A Custom Role for a Cluster or Project
|
# Creating A Custom Role for a Cluster or Project
|
||||||
|
|
||||||
While Rancher comes out-of-the-box with a set of default user roles, you can also create default custom roles to provide users with very specific permissions within Rancher.
|
While Rancher comes out-of-the-box with a set of default user roles, you can also create default custom roles to provide users with very specific permissions within Rancher.
|
||||||
|
|
||||||
@@ -57,7 +60,7 @@ The steps to add custom roles differ depending on the version of Rancher.
|
|||||||
|
|
||||||
1. Click **Create**.
|
1. Click **Create**.
|
||||||
|
|
||||||
## Creating a Custom Global Role
|
# Creating a Custom Global Role
|
||||||
|
|
||||||
### Creating a Custom Global Role that Copies Rules from an Existing Role
|
### Creating a Custom Global Role that Copies Rules from an Existing Role
|
||||||
|
|
||||||
@@ -91,7 +94,7 @@ Custom global roles don't have to be based on existing roles. To create a custom
|
|||||||
|
|
||||||
1. Click **Save.**
|
1. Click **Save.**
|
||||||
|
|
||||||
## Deleting a Custom Global Role
|
# Deleting a Custom Global Role
|
||||||
|
|
||||||
When deleting a custom global role, all global role bindings with this custom role are deleted.
|
When deleting a custom global role, all global role bindings with this custom role are deleted.
|
||||||
|
|
||||||
@@ -105,7 +108,7 @@ To delete a custom global role,
|
|||||||
2. On the **Global** tab, go to the custom global role that should be deleted and click **⋮ (…) > Delete.**
|
2. On the **Global** tab, go to the custom global role that should be deleted and click **⋮ (…) > Delete.**
|
||||||
3. Click **Delete.**
|
3. Click **Delete.**
|
||||||
|
|
||||||
## Assigning a Custom Global Role to a Group
|
# Assigning a Custom Global Role to a Group
|
||||||
|
|
||||||
If you have a group of individuals that need the same level of access in Rancher, it can save time to create a custom global role. When the role is assigned to a group, the users in the group have the appropriate level of access the first time they sign into Rancher.
|
If you have a group of individuals that need the same level of access in Rancher, it can save time to create a custom global role. When the role is assigned to a group, the users in the group have the appropriate level of access the first time they sign into Rancher.
|
||||||
|
|
||||||
@@ -129,3 +132,9 @@ To assign a custom global role to a group, follow these steps:
|
|||||||
1. Click **Create.**
|
1. Click **Create.**
|
||||||
|
|
||||||
**Result:** The custom global role will take effect when the users in the group log into Rancher.
|
**Result:** The custom global role will take effect when the users in the group log into Rancher.
|
||||||
|
|
||||||
|
# Privilege Escalation
|
||||||
|
|
||||||
|
The `Configure Catalogs` custom permission is powerful and should be used with caution. When an admin assigns the `Configure Catalogs` permission to a standard user, it could result in privilege escalation in which the user could give themselves admin access to Rancher provisioned clusters.
|
||||||
|
|
||||||
|
For example, a standard user with the `Configure Catalogs` permission could fork the Rancher [system-charts repository](https://github.com/rancher/system-charts) and add a new version to `rancher-eks-operator` with a ClusterRoleBinding that assigns admin privileges to themselves. After editing the `system-library` catalog in Rancher to the forked version, the standard user would gain administrator access to new EKS clusters.
|
||||||
Reference in New Issue
Block a user