Skip to content

Authorization overview

Since 7.0

MetalSoft implements both Role-Based Access Control and Attribute-Based Access Control.

These are the elements that control access to resources:

  • An admin can assign a single Role to a User at a time. The default role for Users is the built-in “User” role.
  • A Role has one or more Permissions. Roles are shared across multiple users.
  • A Permission consists of:
    • a Subject (a VM, a server, etc.)
    • an Action (Create, List, Read, etc.)
    • a list of Fields (such as “label”) — these are the fields on the Subject’s object that can be manipulated
    • a list of Conditions such as { status: { $in: ['deployed', 'active'] } }

MetalSoft provides a series of built-in Roles and Permissions and allows the creation of custom ones.

Separately, MetalSoft uses multiple forms of authentication:

  1. Built-in
  2. LDAP-based
  3. SAML-based

More than one form of authentication can be active at any given time. Use Global Configurations > Authentication to manage them.

Consult Authentication overview for more details.

Many resources have an owner associated with them. In that case, some resources (such as OS templates and workflows) are not visible to other admins until they are published. A property called visibility controls this. Set the visibility to ‘public’ to share the resource with other users.

Only infrastructures owned by a Billable account can be deployed. Normally, only one account in an organization has billing activated, such as by adding a credit card. An external billing system can also use this flag to determine who needs to be invoiced.

Users also have various Limits associated with them, such as the maximum number of servers an account can provision. MetalSoft adds these to prevent abuse or Denial-of-Service type attacks. Use the Users & Permissions//Limits section to change these limits.

An account typically maps to a company that has multiple Users and includes billing information. An admin can set default Limits on the Account, and all Users inherit those custom limits.

To simplify permission management, users can share access to specific Infrastructures with other users via the Infrastructure > Infrastructure Settings > Sharing, as well as share their entire account.