3.5. 红帽单点登录
MTA 将身份验证和授权委托给 MTA operator 管理的 Red Hat Single Sign-On (RHSSO) 实例。除了控制受管 RHSSO 实例的完整生命周期外,MTA operator 还管理一个专用域的配置,其中包含 MTA 所需的所有角色和权限。
如果在 MTA 管理的 RHSSO 实例中需要高级配置,如 为 User Federation 添加一个供应商或集成身份提供程序,用户可以通过 mta-ui 路由中的 /auth/admin 子路径登录到 RHSSO 管理控制台。用于访问 MTA 管理的 RHSSO 实例的 admin 凭据可以从安装用户界面的命名空间中提供的 credential-mta-rhsso secret 中检索。
通过在管理 MTA 实例的 Tackle CR 中将 rhsso_external_access 参数设置为 True 来创建 MTA 受管 RHSSO 实例的专用路由。
如需更多信息,请参阅 Red Hat Single Sign-On 功能和概念。
3.5.1. 角色和权限 复制链接链接已复制到粘贴板!
下表包含 MTA 查找受管 RHSSO 实例的角色和权限(范围):
| tackle-admin | 资源名称 | Verbs |
| 附加组件 |
delete | |
| adoptionplans |
post | |
| 应用程序 |
delete | |
| applications.facts |
delete | |
| applications.tags |
delete | |
| applications.bucket |
delete | |
| assessments |
delete | |
| businessservices |
delete | |
| dependencies |
delete | |
| identities |
delete | |
| imports |
delete | |
| jobfunctions |
delete | |
| proxies |
delete | |
| reviews |
delete | |
| 设置 |
delete | |
| stakeholdergroups |
delete | |
| stakeholders |
delete | |
| tags |
delete | |
| tagtypes |
delete | |
| tasks |
delete | |
| tasks.bucket |
delete | |
| tickets |
delete | |
| trackers |
delete | |
| 缓存 |
delete | |
| files |
delete | |
| rulebundles |
delete | |
| tackle-architect | 资源名称 | Verbs |
| 附加组件 |
delete | |
| applications.bucket |
delete | |
| adoptionplans |
post | |
| 应用程序 |
delete | |
| applications.facts |
delete | |
| applications.tags |
delete | |
| assessments |
delete | |
| businessservices |
delete | |
| dependencies |
delete | |
| identities |
get | |
| imports |
delete | |
| jobfunctions |
delete | |
| proxies |
get | |
| reviews |
delete | |
| 设置 |
get | |
| stakeholdergroups |
delete | |
| stakeholders |
delete | |
| tags |
delete | |
| tagtypes |
delete | |
| tasks |
delete | |
| tasks.bucket |
delete | |
| trackers |
get | |
| tickets |
delete | |
| 缓存 |
get | |
| files |
delete | |
| rulebundles |
delete | |
| tackle-migrator | 资源名称 | Verbs |
| 附加组件 |
get | |
| adoptionplans |
post | |
| 应用程序 |
get | |
| applications.facts |
get | |
| applications.tags |
get | |
| applications.bucket |
get | |
| assessments |
get | |
| businessservices |
get | |
| dependencies |
delete | |
| identities |
get | |
| imports |
get | |
| jobfunctions |
get | |
| proxies |
get | |
| reviews |
get | |
| 设置 |
get | |
| stakeholdergroups |
get | |
| stakeholders |
get | |
| tags |
get | |
| tagtypes |
get | |
| tasks |
delete | |
| tasks.bucket |
delete | |
| tackers |
get | |
| tickets |
get | |
| 缓存 |
get | |
| files |
get | |
| rulebundles |
get |