이 콘텐츠는 선택한 언어로 제공되지 않습니다.

Chapter 3. Using consolidated roles for configuring User Access


Use the consolidated roles to simplify user access configuration for groups and permissions for various levels of access to the Red Hat Lightspeed services.

3.1. Consolidated roles

The Red Hat Hybrid Cloud Console provides three user access roles with ease of use in mind. These roles help simplify how the Organization Administrator creates groups and permissions for various levels of access to the Red Hat Lightspeed services.

The consolidated roles are as follows:

RHEL viewer: The RHEL viewer role provides users visibility without the ability to make changes. It allows read-only access to Red Hat Lightspeed. You can view system configurations, compliance reports, inventory data, patch information, vulnerabilities, and overall resource states and activities. The only action permitted with this role is to generate activation keys.

RHEL operator: The RHEL operator role allows active management of your Red Hat Lightspeed environment. With this role you can edit system configurations, inventory details, policies, and notification/integration settings. The RHEL operator role allows many of the RHEL administrator role functions, but it is restricted from editing compliance policies, content source templates or policies, or tasks. In addition, the RHEL operator role cannot execute remediation plans.

RHEL administrator: The RHEL administrator role provides comprehensive administrative privileges across your RHEL systems and Red Hat Lightspeed. With this role you can manage system configurations, inventory, compliance policies, notifications, patch management, remediations, malware detection, and advisor recommendations. The RHEL administrator role can also view and modify all vulnerability settings.

See Predefined User Access roles, for the roles included in the Default admin access group.

3.2. Configuring groups with consolidated User Access roles

User Access provides a number of predefined roles that you can add to groups. Three of the predefined roles provide permissions to view, operate, and administer the Red Hat Lightspeed services in the Red Hat Hybrid Cloud Console. Doing so requires modifying the Default access group and creating a new group for each one of the view, operate, and administer permissions.

For a list of predefined roles provided by Red Hat, see section Predefined User Access roles.

Note

The Default access group contains a subset of all predefined roles. For more information, see section

Predefined User Access roles.

When you complete the following steps, you will have a single RHEL Viewer group that contains a single, comprehensive role that grants all the necessary permissions for the group members. You no longer need to manage a group with multiple individual roles.

3.2.1. Preparing the Default access group for consolidated role permissions

Before creating a group for a consolidated role, you must modify the Default access group and remove several roles associated with Red Hat Lightspeed-specific permissions.

Prerequisites

  • You are logged in to the Red Hat Hybrid Cloud Console as a user who has Organization Administrator permission.
  • If you are not an Organization Administrator, you must be a member of a group that has the User Access administrator role assigned to it.
Note

When you make changes to the Default access group its name changes to Custom default access group and is no longer updated with Red Hat defined default roles.

Procedure

  1. Open the settings menu
  2. Click User Access. This opens the Identity and Access Management page.
  3. Under User Access, click Groups. Before you implement the new RHEL roles, modify the Default access group.
  4. Click the Default access group. Remove the following twelve RHEL related default roles from Default access group, which removes those permissions for all users in your organization.

    • Compliance viewer
    • Content Template viewer
    • Directory and Domain Services viewer
    • Inventory Hosts administrator
    • Patch viewer
    • Remediations viewer
    • Repositories viewer
    • Resource optimization user
    • Repositories viewer
    • RHC user
    • RHEL Advisor administrator
    • Vulnerability viewer
  5. After you select the roles to remove, click on the more options menu icon img more options , which is located in the filter action area near the top of the role list, and click Remove.
  6. Confirm the removal. The selected roles and their permissions are deleted from the Default access group and a success message appears. The Default access group is automatically renamed Custom default access group. You can scroll through the Roles list and verify the roles are removed from the Custom default access group.

3.2.2. Creating a new group for RHEL viewers

After modifying the Default access group, which is automatically renamed to Custom default access group, create a new group that provides permissions for RHEL viewers. You can also create additional groups that provide permissions for RHEL operators or RHEL administrators.

Prerequisites

  • If you are not an Organization Administrator, you must be a member of a group that has the User Access administrator role assigned to it.

Procedure

  1. Click Create a group.
  2. Provide a group name and description. For example:

    Group name: RHEL Viewers
    Group description: Users who can view all RHEL services and pages, but cannot execute or edit data
    Copy to Clipboard Toggle word wrap
  3. Follow the wizard to locate and add the RHEL viewer role to the group.
  4. Add members of your organization to this group who you want to have RHEL viewer permissions.
  5. Review the group details and submit. A success message appears.

Verification

Look at the Groups list and confirm that the RHEL Viewer group is now available. You can enter "RHEL" in the Filter by name search to locate a specific group.

맨 위로 이동
Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 문서 정보

Red Hat을 사용하는 고객은 신뢰할 수 있는 콘텐츠가 포함된 제품과 서비스를 통해 혁신하고 목표를 달성할 수 있습니다. 최신 업데이트를 확인하세요.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

Theme

© 2025 Red Hat