Add/remove user roles
Platform administrators can add roles for specified users outside of their own accounts, granting corresponding permissions to those users. They can also remove roles from specified users outside of their own accounts, revoking corresponding permissions.
Note: Only users with the platform administrator role have the permission to add/remove roles for other users. Also, it is not possible to manage the roles of one’s own account.
Add roles for users
-
In the left navigation pane, click Users > User Management.
-
Click the user name to whom you want to add roles.
-
Scroll down to the Role List section and click Add Role.
-
In the pop-up dialog box for adding roles, click
to add a role for the user.Note: You can repeat this step to add multiple roles for the user.
-
Select a system role or custom role to add from the Role Name drop-down list.
Note: The same role can only be added once for the same user. The roles that the user already has will be displayed in the drop-down list but cannot be selected.
-
After selecting the scope of the role’s permissions (cluster, project, or namespace), click Add.
Tip: It is not possible to assign the Cluster Administrator role for the global cluster to a user.
Unbind
-
In the left navigation pane, click Users > User Management.
-
Click the user name from whom you want to remove roles.
-
Scroll down to the Role List section, click Remove next to the role you want to remove, and confirm.