Authorization

These sections show you how to configure the authorization of AxoConsole with different authentication backends.

Authorization is configured in the kcp.rbac.roles section of /var/lib/rancher/k3s/server/manifests/axoflow-config.yaml.

Default configuration

The installer sets up the following default role bindings, which grant full access to users in the admin group of your identity provider:

kcp:
  rbac:
    roles:
      IAMadmin:
        groups:
          - "groups:admin"
      admin:
        groups:
          - "groups:admin"

Verify that this matches your requirements by checking the file:

grep -A20 'rbac:' /var/lib/rancher/k3s/server/manifests/axoflow-config.yaml

Available roles

The following roles are available in AxoConsole by default:

  • IAMadmin: Can manage the roles and permissions to access AxoConsole. Only this role can make changes on the Settings > Roles page.

  • admin: Has full access to AxoConsole, but has only read access to the Settings > Roles page.

  • infrastructureManager: Can manage the infrastructure (without the permissions to view or tap log contents, or to rehydrate data). Has full access to the following pages: Activity Logs, Alerting, Routers, Sources, Flows, Provisioning, Search Logs. Can tap into service logs which may contain event payload.

  • infrastructureViewer: Similar to infrastructure-manager, but can only view the pages.

  • contentManager: Can view log content and manage content related details like flows (without the permissions to manage infrastructure, but including access to view infrastructure details).

    • Has full access to the Rehydration page.
    • Can view and modify Flows, but can’t create or delete them.
    • Can view Routers, Sources, Search Logs, Analytics.
    • Can tap into logs.
  • contentViewer: Can view content like analytics, log search, log tapping (without the permissions to manage or view infrastructure details).

    • Can view Search Logs, Analytics.
    • Can tap into logs.

If you need other roles, contact the Axoflow support team. Composing other roles is possible as part of a custom integration.

Customize role bindings

To assign additional groups to a role, add them to the groups list. The group format depends on your authentication backend:

  • Built-in identity provider (axoidp) and LDAP: groups:<group-name>
  • Email domain: emaildomain:<domain>

Edit the manifest and save — k3s picks up the change automatically:

sudo vi /var/lib/rancher/k3s/server/manifests/axoflow-config.yaml