Skip to main content
This page describes the fields of the AccessPolicy resource. For how Omni evaluates access policies, complete examples, and the Kubernetes RBAC setup that access policies depend on, see Manage Access Policies (ACLs).
ACLs grant access but do not revoke it. Kubernetes groups other than system:masters have no permissions until they are bound to a Role or ClusterRole through Kubernetes RBAC.

AccessPolicy

The AccessPolicy is a single resource containing a set of user groups, a set of cluster groups, a list of matching rules, and a list of tests.

UserGroup

A UserGroup is a group of users.

User

A User is a single user.
name, match, and labelselectors are mutually exclusive. Set only one of them for each user.Common label selector forms are key=value (the label has this value), key (the label exists), and !key (the label does not exist). Other operators, such as !=, in, and notin, are also supported.

ClusterGroup

A ClusterGroup is a group of clusters.

Cluster

A Cluster is a single cluster.
name and match are mutually exclusive. Set only one of them for each cluster.
match: "*" matches all clusters. A rule whose cluster group uses match: "*" also applies its role to lists of resources across all clusters. Other patterns, such as prod-*, do not, even when they match every cluster.

Rule

A Rule is a set of users, clusters, an Omni role, and Kubernetes impersonation groups. The reserved prefix group/ references a user group in users or a cluster group in clusters. Entries without the prefix must match a user identity or cluster name exactly.

Role

A Role is the Omni role to grant to the user on the matching clusters. Possible values: None, Reader, Operator, Admin. The Auditor role cannot be assigned by an ACL, because audit log access is account-wide rather than cluster-scoped. A rule that grants Operator or Admin also assigns the Kubernetes group system:masters. A rule without a role grants no role, but still assigns its Kubernetes groups. The user’s effective role on a cluster is the higher of their Omni role and the role granted by the ACL. Downloading a kubeconfig requires at least Reader on the cluster.

Test

A Test is a single test case. Omni runs the tests when the resource is created or updated, and rejects the change if any test fails.

TestUser

A TestUser is the user identity to use in a test case.

TestCluster

A TestCluster is the cluster to use in a test case.

Expected

An Expected is the expected result of a test case.