cloudfoundry / cloudfoundry/docs-uaa

cloud_controller.admin_read_only and cloud_controller.global_auditor permissions are more limited than suggested

Open
#5 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

accepted
Dominant language
HTML
Stars
2
Forks
15
PR merge metrics
No merged PRs in 30d

Description

Creating and Managing Users with the UAA CLI (UAAC) claims the following:

The admin read-only account can view but not modify all Cloud Controller API resources.

and

The global auditor account has read-only access to all Cloud Controller API resources but cannot access secret data such as environment variables.

According to currently outstanding issues (linked below), both read-only and global auditor roles are not able to get stats for app instances/processes:

Ideally, the doc would reflect this limitation.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Creating and Managing Users with the UAA CLI (UAAC) page linked in the issue, then review the linked read-only and global auditor stories about app-instance/process stats. Update the role descriptions so their inability to retrieve stats is accurately reflected, and confirm both statements no longer imply unrestricted read-only access.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.