Manage Kubernetes resource access
Manage access to Kubernetes resources in NetApp Backup and Recovery at the cluster or resource level. You manage access to cluster resources by associating clusters with folders or projects during discovery in NetApp Console and by assigning users the appropriate roles. Manage resource access at the namespace level by registering a namespace as an IAM resource associated with a project or folder.
For information about associating a cluster with an IAM folder or project, refer to Discover Kubernetes workloads.
Backup and Recovery namespace-level resource access for Kubernetes resources is controlled by the folder or project that you associate with the namespace when you register the namespace for access control. After the namespace is associated with a folder or project, users who have the appropriate NetApp Console and Backup and Recovery roles for that scope can access the namespace and its protected resources.
Backup and Recovery roles and what they allow with Kubernetes workloads
For a Kubernetes cluster or namespace associated with a folder or project, the specific Backup and Recovery role a user holds on that folder or project determines what they can do. For more information on Backup and Recovery roles, refer to Backup and Recovery roles in NetApp Console.
|
|
The Backup and Recovery clone admin role is not used with Kubernetes workloads. |
| Role | Scope of view access | Actions permitted |
|---|---|---|
Backup and Recovery Super Admin |
Full view of clusters, namespaces, and applications in scope |
View, create application, protect (create/remove protection), and restore |
Backup and Recovery Viewer |
View for clusters and namespaces in scope only |
View only. Cannot create, protect, or restore. |
Backup and Recovery Backup Admin |
Full view of clusters, namespaces, and applications in scope |
View, create application, and protect (create/remove protection). Cannot restore. |
Backup and Recovery Restore Admin |
Full view of clusters, namespaces, and applications in scope |
View and restore only. Cannot create applications or protection policies. |
Associate a Kubernetes namespace with a folder or project
Associate a namespace with a folder or project so that access control applies to that scope.
Required NetApp Console role
Backup and Recovery super admin. If you are protecting data stored on a Cloud Volumes ONTAP cluster, the Cloud Volumes ONTAP Admin role is also required. Learn about Backup and recovery roles and privileges. Learn about NetApp Console access roles for all services.
-
From the NetApp Console menu, select Protection > Backup and recovery.
-
Under Workloads, select the Kubernetes tile.
-
In the inventory, select the Namespaces menu.
-
Choose one or more namespaces that you want to register for access control, and enable the check box for each.
-
Select Register for access control.
-
Optionally, select a folder or project to determine where access control applies to this namespace. If you don't select a folder or project, the namespace IAM resource is registered, but not added to a folder or project:
-
Folder: Select this option to control user access to namespace resources at the folder level, and select a folder from the list.
If a Kubernetes cluster or namespace is associated with a folder, users also need the Backup and Recovery viewer role for the project selected in the top-right project selector. This project-level access enables users to open the Backup and Recovery home page. Roles assigned at the folder level (for example, Backup and Recovery backup admin) determine what users can do after they enter the workload page, but do not grant access to the page by themselves. -
Project: Select this option to control user access to namespace resources at the project level, and select a project from the list.
Learn more about organizational components in NetApp Console.
-
-
Select Register.