How to Use SingleStore Helios RBAC
On this page
The following sections outline the steps for using RBAC at the organization and Cluster group levels.
To configure RBAC:
-
On the Cloud Portal, navigate to Clusters.
-
Select the three dots under the Actions column for your cluster, and then select Access & Security from the list.
-
On the Access tab, configure RBAC in the User Management section.
Organization Level
SingleStore offers different organizational level access for users in the Shared, Standard, and Enterprise editions.
For Users in Shared Edition
Invite New Users
-
Navigate to the Users & Teams option from the Organization menu at the top.
-
Select Add Member.
-
Enter the new user's email address and then select the default team that this member should be invited to.
-
By default, every user invited to the organization is added to the Organization Owners team and assigned the Owner role.
-
To change or add roles for each user, navigate to Teams, then select the team the user needs to be part of in the organization.
-
Select Edit Team, select the user from the list, and then select Update Team.
Create a New Team
-
Navigate to the Users & Teams option from the Organization menu at the top.
-
Switch to the Teams tab.
-
Select Create New Team.
-
Add the details for Team Name and Team Description.
-
Select default members in the team.
-
Select Create Team to complete the creation.
Update the Members of Existing Teams
-
Navigate to the Users & Teams option from the Organization menu at the top.
-
Switch to the Teams tab.
-
Select the ellipsis (three dots) in the Actions column and select View Team.
Alternatively, you can directly select the Team Name in the first column. -
Select Edit Team on the top right.
-
Add or remove existing members of the team as required.
-
Select Update Team to save changes.
-
For Users in Standard and Enterprise Editions
Invite New Users
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Select Add User.
-
Enter the new user's email address in User Email and then select the team from the Teams list that this user should be invited to.
Selecting the team is optional. -
By default, every user invited to the organization is added to the Organization Owners team and assigned the Owner role.
-
To change or add roles for each user, navigate to Teams, then select the team the user needs to be part of in the organization.
-
Select Edit Team, select the user from the list, and then select Update Team.
Create a New Team
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Teams tab.
-
Select Create New Team.
-
Add the details for Team Name and Team Description.
-
Select the users in the team.
-
Select Create Team to complete the creation.
Update the Users of Existing Teams
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Teams tab.
-
Select the ellipsis (three dots) in the Actions column and select View Team.
Alternatively, you can directly select the team name in the Name column. -
Select Edit Team on the top right.
-
Add or remove existing users of the team as required.
-
Select Update Team to save changes.
-
Custom Role
Create a Custom Role
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Roles tab.
-
Select Create Custom Role.
-
In the Create Role dialog box,
-
Enter the Name and Description of the role.
-
Valid Names must start with a letter or underscore and can include letters, numbers, underscores, hyphens, or spaces.
-
Select the resource among Organization, Cluster Group, Team, and Secret for which you want to create the role.
-
Set the permissions for the role based on the selected resource.
-
Select Create Role to complete the creation.
-
Edit a Custom Role
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Roles tab.
-
Select Custom from the Role list to edit the role.
-
Select the role name in the Name column.
-
Select Edit Role.
-
Update the Description and set new permissions.
-
Select Update Role to save changes.
-
Delete a Custom Role
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Roles tab.
-
Select Custom from the Role list to edit the role.
-
Select the role name in the Name column.
-
In the Actions column, from the ellipsis (three dots), select Delete Role.
Role Management
You can add or revoke both predefined and custom roles.
Add a Role for a User
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Users tab.
-
Select a user in the Name column.
-
Select the resource among Organization, Cluster Group, Team, and Secret for which you want to add the role.
-
Select Add Role.
Add Role For <Resource> dialog appears. -
Follow the actions for different resources:
Resource
Action
Organization
-
Select a role from the Role list.
Select Add Role to add a role in the organization. -
Select Add Role to add a role in the organization.
Cluster Group
-
Select a cluster group from the Cluster Group list.
-
Select a role from the Role list.
-
Select Add Role to add a role in the cluster group.
Team
-
Select a team from the Team list.
-
Select a role from the Role list.
-
Select Add Role to add a role in the team.
Secret
-
Select a secret from the Secret list.
-
Select a role from the Role list.
-
Select Add Role to add a role in the team.
-
Revoke a Role for a User
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Users tab.
-
Select a user in the Name column.
-
Select the resource among Organization, Cluster Group, Team, and Secret for which you want to revoke the role.
-
Find the role you want to delete.
-
In the Actions column corresponding to the role you want to delete, select the trash bin icon.
-
Select Revoke to revoke/delete a role.
Add a Role for a Team
You cannot add roles on default teams.
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Teams tab.
-
Select a team in the Name column.
-
Select the resource among Organization, Cluster Group, Team, and Secret for which you want to add the role.
-
Select Add Role.
Add Role For <Resource> dialog appears. -
Follow the actions for different resources:
Resource
Action
Organization
-
Select a role from the Role list.
Select Add Role to add a role in the organization. -
Select Add Role to add a role in the organization.
Cluster Group
-
Select a cluster group from the Cluster Group list.
-
Select a role from the Role list.
-
Select Add Role to add a role in the cluster group.
Team
-
Select a team from the Team list.
-
Select a role from the Role list.
-
Select Add Role to add a role in the team.
Secret
-
Select a secret from the Secret list.
-
Select a role from the Role list.
-
Select Add Role to add a role in the team.
-
Revoke a Role for a Team
-
Navigate to the Users & Permissions option from the Organization menu at the top.
-
Switch to the Teams tab.
-
Select a team in the Name column.
-
Select the resource among Organization, Cluster Group, Team, and Secret for which you want to revoke the role.
-
Find the role you want to delete.
-
In the Actions column corresponding to the role you want to delete, select the trash bin icon.
-
Select Revoke to revoke/delete a role.
Cluster Level
Add New Users
-
Navigate to Clusters in the left navigation pane.
-
Select the cluster that you want to invite the user to.
-
Select the Access & Security tab.
-
Select Grant Access under the User management section.
-
Fill in the details in the Grant Access to cluster dialog box.
-
Select User or Team from the list, and select a role.
This applies to the cluster-level roles that need to be added. -
Select Grant Access to save the changes.
-
You will be able to see the member or team added.
Update Members in an Existing Cluster
-
Navigate to Clusters in the left navigation pane.
-
Select the cluster from the cluster list that you want to update the member.
-
Select the Access & Security tab.
-
Select the ellipsis (three dots) in the Actions column and then select Edit Roles next to the member to change the role of that member.
To remove the member’s access from the cluster completely, select Revoke all Roles. -
In the Edit Roles, change the role for the member.
-
Select Update to save the changes.
Enabling RBAC for New and Existing Organizations
RBAC is enabled for all Organizations.
Pre-defined teams are created and granted common roles when RBAC is enabled.
For new organizations, the initial users will be added to the Organization Owners team, which grants full access to all user actions.
New users can be invited to join any team(s).
When users are added to an organization or a cluster group, synchronization takes place in the engine and they are added to the corresponding user groups in the backend.
Last modified: