Chapter 3. Approved access
You can use the Approved Access feature to review, approve, or deny elevated access requests from Red Hat Site Reliability Engineering (SRE) to your Red Hat OpenShift Service on AWS classic architecture cluster resources.
Red Hat SRE typically does not require elevated access to systems as part of normal operations to manage and support Red Hat OpenShift Service on AWS classic architecture clusters. Elevated access gives SRE the access levels of a cluster-admin role.
SRE creates elevated access requests either in response to a customer-initiated support ticket or in response to alerts received as part of the standard incident response process.
When Approved Access is enabled and an SRE creates an access request, cluster owners receive an email notification informing them of a new access request. The email notification contains a link allowing the cluster owner to quickly approve or deny the access request. You must respond in a timely manner otherwise there is a risk to your service-level agreement (SLA) for Red Hat OpenShift Service on AWS.
- Pending access requests are available in the Hybrid Cloud Console on the clusters list or Access Requests tab on the cluster overview for the specific cluster.
Denying an access request requires you to complete the Justification field. In this case, SRE cannot directly act on the resources related to the incident. Customers can still use Customer Support to help investigate and resolve any issues.
3.1. Enabling approved access for ROSA clusters by submitting a support case Copy linkLink copied to clipboard!
Enable the Approved Access feature for your Red Hat OpenShift Service on AWS clusters by creating a support ticket so that you can control when Red Hat Site Reliability Engineering (SRE) accesses your cluster resources.
Procedure
- Log in to the Customer Support page of the Red Hat Customer Portal.
- Click Get support.
On the Cases tab of the Customer support page:
- Optional: Change the pre-filled account and owner details if needed.
- Select the Configuration category and click Continue.
Enter the following information:
- In the Product field, select Red Hat OpenShift Service on AWS classic architecture.
- In the Problem statement field, enter Enable ROSA Access Protection.
- Click See more options.
- Select OpenShift Cluster ID from the drop-down list.
Fill the remaining mandatory fields in the form:
What are you experiencing? What are you expecting to happen?
- Fill with Approved Access.
Define the value or impact to you or the business.
- Fill with Approved Access.
- Click Continue.
- Select Severity as 4(Low) and click Continue.
- Preview the case details and click Submit.
3.2. Reviewing an access request from an email notification Copy linkLink copied to clipboard!
To control when Red Hat Site Reliability Engineering (SRE) can access your cluster resources, you can review and respond to access requests from email notifications.
Procedure
- Click the link within the email to bring you to the Hybrid Cloud Console.
In the Access Request Details dialog, click Approve or Deny under Decision.
NoteDenying an access request requires you to complete the Justification field. In this case, SRE cannot directly act on the resources related to the incident. Customers can still use the Customer Support to help investigate and resolve any issues.
- Click Save.
3.3. Reviewing an access request from the Hybrid Cloud Console Copy linkLink copied to clipboard!
You can use the Hybrid Cloud Console to approve or deny access requests for your Red Hat OpenShift Service on AWS clusters to control when Red Hat Site Reliability Engineering (SRE) can access your cluster resources.
Procedure
- Navigate to OpenShift Cluster Manager and select Cluster List.
- Click the cluster name to review the Access Request.
- Select the Access Requests tab to list all states.
- Select Open under Actions for the Pending state.
In the Access Request Details dialog, click Approve or Deny under Decision.
NoteDenying an access request requires you to complete the Justification field. In this case, SRE cannot directly act on the resources related to the incident. Customers can still use the Customer Support to help investigate and resolve any issues.
- Click Save.