RBAC (Role Based Access Control) for VCP

RBAC is a way to provide an access to the logged in user in vCenter server. The administrator user can create roles and assign privileges to the user for role based access control.

In vCenter plugin, we can manage RBAC by creating specific privileges, like read only snapshot dashboard, Limited access to Datastore operations.

Here, In this case, we need to create privileges on vCenter server and assign these to some role. After this, we can create a user and add it to the role which we have created to manage the VCP.

We can add tag inside the plugin.xml. Using this tag, we can add particular permissions to vCenter entities like Datastore, Hostsystem, VM etc. Once tag is added in plugin.xml file and user has this privilege then he can perform the operation on vCenter entity.

There can be multiple privileges per entity. This privilege will be very specific to vCenter plugin.
In this scenario, we have to deal with only vCenter server user. Storage user will not come into the picture.

There is one more way to manage RBAC, using directory services (AD, LDAP). In this scenarios. AD server has to be bind with vCetner SSO (Single Sign On) and Storage.

Let’s go through the diagram mentioned below,

In diagram, please follow the numbers

Here User1 is logged in vsphere web client which will be passed to SSO and then to the AD server for authentication. Once the user is authenticated, we can land up to VCP dashboard from which we can perform operations on the Storage server. While executing REST APIs of Storage, we have to get the user session key from vsphere web client and pass it to REST API through authorization header. Storage server will validate the user against AD server and then execute the REST API.

Here we need to configure our storage and SSO with the AD server. Unless there is not a connection between the AD and Storage server we will not be able to authenticate the user which is logged in vsphere web client.

 
Share:

Related Posts

Enhancing vCenter Capabilities with VMware vCenter Plugins: A Deep Dive

 vCenter Server is one of the most powerful tools in VMware’s product portfolio, enabling efficient management of virtualized environments. One of the most used features in vCenter is the vCenter plugin, which extends the capabilities by providing custom features such as 3rd Party system discovery, and provisioning, providing a unified view, allowing administrators to manage vSphere, and 3rd Party systems seamlessly.

Share:
5G: Network Slicing, Its Management, and Orchestration

5G: Network Slicing, Its Management, and Orchestration

5G Network Slicing is a key characteristic in 5G which is realized through the integration of virtualization and software-defined networking technologies. The management and orchestration of 5G network slicing is a complex task that involves a combination of software and hardware solutions. Read this blog to explore the concept of Network Slicing and its management, orchestration aspects mainly focusing on management models.

Share:

5G Network Slicing: A Gamechanger for Telcos

5G network slicing is a powerful tool that can help telcos differentiate themselves from their competitors by offering more tailored and customized services to their customers. It has the potential to be a gamechanger for telcos, and we can expect to see more and more telcos investing in this technology in the coming years. Read the latest blog to explore how 5G Slicing can be a gamechanger for the Telco Industry in the future.

Share:
The-Many-Layers-of-Virtualization

The Many Layers of Virtualization

Virtualization has found many takers in the tech industry, but there are still many who are unaware of its full potential. In this article, we explore the types of virtualizations, its benefits and its use cases. Read on…

Share:
Testing-Storage-Replication-Adapter-for-Site-Recovery-Manager-

Testing Storage Replication Adapter for Site Recovery Manager

Explore the intricacies of testing the storage replication adapter, which is usually installed on the VMware Site Recovery Manager – a disaster recovery management solution.

Share:

ServiceNow Integration to Accelerate Your Business Growth

What has helped us excel as ServiceNow technology partners, especially in the storage and networking space, has been our storage DNA.

Share: