How to grant administrator access to Automation Hub and Automation Service Catalog with RH-SSO enabled ?
Environment
- AAP 2.x with RH-SSO enabled
Issue
- The RH-SSO user is not able to perform admin level jobs neither in Automation Hub GUI nor in Automation Service catalog
Resolution
-
Setting administrator for the Automation Hub in the RH-SSO sever is done through the role mapping.
-
To give a user or group this role mapping follow the below steps:
-
Hit the RH-SSO GUI - > Navigate to ansible-automation-platform realm in SSO client.
-
navigate to Manage section -> choose Users or Groups
-
Click view all users -> Select the user -> Edit
-
navigate to Role Mappings -> Client Roles
-
using the drop-down menu, select
automation-hub
andautomation-catalog
client role for Automation Hub and Service catalog respectively -
The available roles for Automation Hub is
hubadmin
, selecthubadmin
from the Available Roles -> HitAdd Selected
button -
The available roles for Service Catalog are :
- approval-admin
- approval-approver
- catalog-admin
- catalog-user
- uma_protection
-
Select the appropriate role from the Available Roles -> Hit Add Selected button
-
-
Now the sso user (test_user) will be able to perform admin level jobs both in Private Automation Hub and Automation Service catalog
This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.