Skip to content

Add more custom global role information#2297

Open
JonCrowther wants to merge 3 commits into
rancher:mainfrom
JonCrowther:global-role-guide
Open

Add more custom global role information#2297
JonCrowther wants to merge 3 commits into
rancher:mainfrom
JonCrowther:global-role-guide

Conversation

@JonCrowther
Copy link
Copy Markdown
Contributor

There's a few issues that this encompasses. It unblocks rancher/dashboard#9728, but the information added is from

Reminders

  • See the README for more details on how to work with the Rancher docs.

  • Verify if changes pertain to other versions of Rancher. If they do, finalize the edits on one version of the page, then apply the edits to the other versions.

  • If the pull request is dependent on an upcoming release, remember to add a "MERGE ON RELEASE" label and set the proper milestone.

Description

Over the last few releases of Rancher, we've introduced new fields to GlobalRoles that allow advanced customization. I have added more details about those fields so users can understand how to use them.

Comments

While some of these features were available in previous Rancher versions, 2.15 will be the first where all the fields exist and will be visible in the UI. So I'm not sure if I should add these to the versioned docs as well.


#### GlobalRole Permissions for Fleet Workspaces

GlobalRoles can grant access to Fleet workspaces in each downstream cluster with the field `inheritedFleetWorkspacePermissions`. This allows users to deploy Fleet resources in all workspaces except `fleet-local`. The field is made up of two parts:
Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was wondering if I should add a link to the fleet docs from here? There's not a lot of fleet related info in these docs.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can't find the use of inheritedFleetWorkspacePermissions in the fleet docs. I could only find https://fleet.rancher.io/how-tos-for-operators/multi-user#_isolated_workspaces_in_rancher where namespacedRules is used to provide access to specific fleet workspaces

raulcabello
raulcabello previously approved these changes Apr 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants