cloudfoundry / cfar-proposals

Repository for Cloud Foundry Application Runtime Proposals
7 stars 3 forks source link

New CF RBAC space-scoped granular roles #22

Open piyalibanerjee opened 3 years ago

piyalibanerjee commented 3 years ago

Proposal ACCEPTED

Proposal Name

New CF RBAC space-scoped granular roles

TL;DR Summary

As a CF space manager, I want to have fine-grained control on the authorizations of my space users, so that I can grant only the actually required authorizations and thus avoid issues like leakage of credentials, unauthorized access to critical data, corruption of data by mistake (e.g. deletion of service instances).

Proposed role(s): Space operator (name still being decided)

Proposal URL

https://docs.google.com/document/d/1isfsSWvF8xDU0G69k4MqB3o5c2vB0P3Vbi79W0yvqFQ/edit

Point of Contact

@piyalibanerjee @monamohebbi @jenspinney [PLACEHOLDER: point of contact from SAP]

piyalibanerjee commented 3 years ago

There are a few options for what the space operator role can be called. Please pick an option from the poll below:

If there are any other suggestions, please leave them in comments here!

Note: Alternatives to 'space operator' name were suggested as a result of the concern about 'operator' being an overloaded/overused term in CF.

monamohebbi commented 3 years ago

Detailed proposal for the Space Application Supporter: https://docs.google.com/spreadsheets/d/1w07-1nlEXYzeDseT_BEKaT2T-QC-wZhNXrX4JPRrAYM/edit?usp=sharing