Skip to content

Latest commit

 

History

History
 
 

2.5-rbac

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Workshop Exercise - Role-based Access Control (RBAC)

Read this in other languages:
uk English, japan日本語, brazil Portugues do Brasil, france Française, Español Español.

Table of Contents


Objective

In this exercise, you'll explore how Ansible Automation Controller handles user and group management through Role-Based Access Control (RBAC). This ensures proper delegation of rights while keeping automation secure.


Guide

Ansible Automation Controller Users

There are three types of users in Ansible Automation Controller:

  • Normal User: Has read and write access limited to assigned inventories and projects.
  • Ansible Automation Platform Auditor: Read-only access to all objects within the automation controller environment.
  • Ansible Automation Platform Administrator: Full admin privileges over the entire automation controller installation.

Let's create a user:

  1. Navigate to Access Management -> Users.

  2. Click the Create user button.

  3. Fill in the following values:

    Parameter Value
    Username wweb
    Password ansible
    Confirm Password ansible
    First Name Werner
    Last Name Web
    Email [email protected]
    Organization Default
    User Type Normal User
  4. Click Create user.

create user


Ansible Automation Controller Teams

Teams are subdivisions of an organization that include users, projects, credentials, and permissions, helping to implement RBAC efficiently.

Create a Team:

  1. Navigate to Access Management -> Teams.
  2. Click the Create team button and create a team named Web Content within the Default organization.
  3. Click Create team.

Add a User to the Team:

  1. Select the Web Content team.
  2. Go to the Users tab and click Add users.
  3. In the Add users window, choose wweb, then click Add users.

add user


Granting Permissions

To grant users the ability to execute tasks, permissions need to be set.

Grant Permission to Use a Template:

  1. Navigate to Automation Execution -> Templates.
  2. Select the template Create index.html.
  3. Click the User Access tab.
  4. Click Add roles.
  5. Select the wweb user and click Next.
  6. Choose the roles JobTemplate Admin and/or JobTemplate Execute, depending on the required level of access, click Next.
  7. Review the selections and click Finish.

Testing Permissions

Now, log out and log in again as the wweb user.

  1. Navigate to Templates. You should only see the Create index.html template listed.
  2. Run the job by clicking the rocket icon. Enter the required values for the survey questions and launch the job.
  3. After completion, check the Jobs view for the expected changes.

To verify the result, use curl on the control host to check the webserver content on node1:

#> curl http://node1

Just recall what you have just done: You enabled a restricted user to run an Ansible playbook

  • Without having access to the credentials

  • Without being able to change the playbook itself

  • But with the ability to change variables you predefined!

Effectively you provided the power to execute automation to another user without handing out your credentials or giving the user the ability to change the automation code. And yet, at the same time the user can still modify things based on the surveys you created.

This capability is one of the main strengths of Ansible automation controller!


Navigation
Previous Exercise - Next Exercise

Click here to return to the Ansible for Red Hat Enterprise Linux Workshop