Identity and access management migration during upgrade
When upgrading from a version of Ansible Automation Platform that predates the platform gateway, Identity Access Management (IAM) data, including users, teams, organizations, their memberships, and associated roles, is migrated from automation controller and automation hub to platform gateway.
This migration establishes automation controller as the primary source of IAM data for platform gateway, ensuring continuity of user memberships and appropriate platform-level role assignments.
If your current version is more than one minor release behind the target version, upgrade directly to the target version rather than performing intermediate upgrades. A direct upgrade is less complex.
- Upgrade from 2.4 to 2.6
It is possible for customers to upgrade directly from the latest 2.4 version to 2.6. On startup, 2.6 platform services rename their service-specific roles to platform-wide roles, as shown in the following table. - Upgrade from 2.5 to 2.6
When upgrading from Ansible Automation Platform 2.5 to 2.6, existing authenticators and their mappings in platform gateway continue to function as they are, with no changes being imported. - Verify assigned permissions after upgrading
It is imperative that administrators verify the assigned permissions for all teams in the platform-wide authentication gateway immediately after the upgrade: - The MANAGE_ORGANIZATION_AUTH setting
The automation controller setting previously called Organization Admins Can Manage Users and Teams in the UI (orMANAGE_ORGANIZATION_AUTHin the API) controls whether an organization administrator can create users and teams.