Authorization overview
Since 7.0
MetalSoft implements both Role-Based Access Control and Attribute-Based Access Control.
Concepts and relationships
Section titled “Concepts and relationships”These are the elements that control access to resources:
- An admin can assign a single Role to a User at a time. The default role for Users is the built-in “User” role.
- A Role has one or more Permissions. Roles are shared across multiple users.
- A Permission consists of:
- a Subject (a VM, a server, etc.)
- an Action (Create, List, Read, etc.)
- a list of Fields (such as “label”) — these are the fields on the Subject’s object that can be manipulated
- a list of Conditions such as
{ status: { $in: ['deployed', 'active'] } }
Roles and Permissions
Section titled “Roles and Permissions”MetalSoft provides a series of built-in Roles and Permissions and allows the creation of custom ones.
Authentication methods
Section titled “Authentication methods”Separately, MetalSoft uses multiple forms of authentication:
- Built-in
- LDAP-based
- SAML-based
More than one form of authentication can be active at any given time. Use Global Configurations > Authentication to manage them.
Consult Authentication overview for more details.
Resource ownership
Section titled “Resource ownership”Many resources have an owner associated with them. In that case, some resources (such as OS templates and workflows) are not visible to other admins until they are published. A property called visibility controls this. Set the visibility to ‘public’ to share the resource with other users.
The “Billable” account
Section titled “The “Billable” account”Only infrastructures owned by a Billable account can be deployed. Normally, only one account in an organization has billing activated, such as by adding a credit card. An external billing system can also use this flag to determine who needs to be invoiced.
User limits
Section titled “User limits”Users also have various Limits associated with them, such as the maximum number of servers an account can provision. MetalSoft adds these to prevent abuse or Denial-of-Service type attacks. Use the Users & Permissions/
Accounts
Section titled “Accounts”An account typically maps to a company that has multiple Users and includes billing information. An admin can set default Limits on the Account, and all Users inherit those custom limits.
Delegation
Section titled “Delegation”To simplify permission management, users can share access to specific Infrastructures with other users via the Infrastructure > Infrastructure Settings > Sharing, as well as share their entire account.