Skip to content

want way to delegate Fleet access #3275

@davepacheco

Description

@davepacheco

Right now, I believe the user that gets created in the recovery Silo during rack setup gets the "fleet admin" role. That user should have the privilege to grant "fleet admin" to anybody else (including users/groups in other Silos), but they have no way of knowing the identity of a user or group in another Silo. (And it's not clear that they should. See #1340.)

However we do it, we want some way of having this user delegate "Fleet Admin" to users or groups in other Silos. That way operators don't need to use the recovery Silo (which bypasses their IdP) to manage the rack.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions