Document if jobs can be hidden but be executed from other
-
Alex-SF
- Tag changed from documentation to customer request, documentation
-
Alex-SF
The underlying goal is to reduce the clutter in the job list. For example, there may be a handful of top level processes that should be visible. These top level jobs may be constructed from lower level "helper jobs" that should not be visible since they should normally be run by themselves.
-
Alex-SF
Adding job definition describing trivial multi-job workflow structure in a group named "#306".
The following aclpolicy hides the jobs that are not meant to be visible in the gui.
<policies> <policy description="User group that has limited access."> <context project="*"> <command group="#306" job="Restart" actions="workflow_run,workflow_read"/> <command group="#306" job="stop" actions="workflow_run"/> <command group="#306" job="stop" actions="workflow_run"/> </context> <by> <group name="user"/> </by> </policy> </policies> -
Greg Schueler
any job can be run as a subjob (auth is not checked)
also, authorization checks for grails actions (pages) use the mapped roles, not the aclpolicy. so, e.g. you can still view the /job/show/id page for any of those jobs where there is no workflow_read authorization. Likewise, mapped roles must assign workflow_update to one of the user's roles to be able to edit a job, even if aclpolicy allows * actions.
another point:
Job listings are filtered by aclpolicy. So the main Jobs page will not show unauthorized jobs. Also, job reference selection in the job edit page will not show unauthorized jobs.
-
Deleted User
- State changed from new to resolved
(from [bf290717af15fc03592da801708b615fcaa13eeb]) Added example in an admin section: "Access control policy actions example" [#306 Document if jobs can be hidden but be executed from other state:resolved] https://github.com/dtolabs/rundeck/commit/bf290717af15fc03592da8017...
-
Deleted User
(from [21709b23ce0ed9edde92d93e09c27bab0ec82ea8]) Added an example to the admin manual describing how to use workflow policy actions. [#306 Document if jobs can be hidden but be executed from other state:resolved] https://github.com/dtolabs/rundeck/commit/21709b23ce0ed9edde92d93e0...
Please Sign in or create a free account to add a new ticket.
With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.
