Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS Web Administration Guide

Roles

You can permit and limit access to administrative areas of your cluster on a per-user basis through roles. OneFS includes several integrated administrator roles with predefined sets of privileges that cannot be modified. You can also create custom roles and assign privileges to those roles.

The following list describes what you can and cannot do through roles:

  • You can assign privileges and subprivileges to a role.
  • You can assign privileges and subprivileges to a role as execute/read/no permission, even if the privilege or subprivilege is write by default.
  • You can create custom roles and assign privileges and subprivileges to those roles.
  • Using the WebUI, you can copy an existing role.
  • If the users can authenticate to the cluster, you can add any user or group of users, including well-known groups, to a role.
  • You can add a user or group to more than one role.
  • You cannot assign privileges and subprivileges directly to users or groups.

When a user belongs to multiple roles, that user's overall privilege consists of the total of all the sets of privileges set for all the roles to which the user belongs. If a particular privilege is configured in multiple roles, the user is granted the highest permission. A top-level or parent privilege that was explicitly assigned to a role has precedence over a privilege or subprivilege that is inherited by the role.

OneFS determines privilege as follows:
  1. OneFS obtains the union of all sets of privileges for all the roles that the user belongs to.
  2. OneFS recalculates the inherited privileges and subprivileges for every explicitly granted parent privilege.

If you explicitly grant a new privilege to a role, OneFS recalculates the inherited privileges based on the new privilege.

NOTE When OneFS is first installed, only users with root- or admin-level access can log in and assign users to roles.

What you can do with privileges through roles applies equally to subprivileges.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\