ABAC/ZTKA - Custom Roles - Rafay Product Documentation

Custom Roles

Custom roles allow Org Admins to overlay a specific set of ZTKA or ABAC policies to a base role ( RBAC Role).

⚠️ Important

Create New Role

Perform the below steps to create a new custom role:

Important
For ABAC (Attribute-based access, only Namespace Admin and Namespace Read Only base roles are supported.

Once the details are saved, the policy is applied to the selected roles and listed as shown below. You can edit the details or delete the custom role if required using the respective icons

On successful custom role creation, now admins can assign the roles to the required users or groups

Custom Role behaviour in Shared projects

The behavior of role combinations involves the interaction among multiple roles assigned to users or entities across different projects. This interaction determines how their permissions and access rights are amalgamated, prioritized, and enforced within a cluster.

Below is an example illustrating how different roles are applied when executing kubectl commands on clusters within various projects:

Scenario 1: Single Project with Custom and Base Roles

Scenario 2: Multiple Projects with Different Roles

Scenario 3: Shared Cluster with Multiple Project Roles