Skip to content

RbacRoleGroup

The RbacRoleGroup resource creates Active Directory Global security groups. These are typically used for role-based access control — granting groups of users specific permissions on resources.

Structure

- type: RbacRoleGroup
  name: roleauditor                            # unique identifier within the RGT
  groupName: "{{deployment.shortid}}-auditor"  # AD group name (supports expressions)
  members:                                     # optional, members to add to the group
    - user-foo                                 # reference users or groups within the same domain
Key Required Description
type Yes Must be RbacRoleGroup
name Yes Unique identifier within the RGT (used in expressions)
groupName Yes The actual AD group name. Supports expressions.
members No List of users or groups to add as members. Supports expressions. No domain needed. Same-domain membership only due to global security group.

Naming Format

The final AD group name is determined by combining the AD_RBACROLEGROUP_FORMAT variable with groupName:

  • Format variable: AD_RBACROLEGROUP_FORMAT uses {0} as a placeholder for the groupName value
  • Default: {0} (the groupName is used as-is)
  • Example: If AD_RBACROLEGROUP_FORMAT is .{{tenant.name}}-{{deployment.shortid}}-{0}-g and groupName is foo, the final name is .acme-0fa0bb-foo-g

The group is created in the AD_GROUP_ROLE_OU organizational unit.

Reference Format

Use {{rbacrolegroup.<name>.<property>}} to reference an RBAC group in expressions.

Given a group with name: rbacfoo, groupName: foo, and AD_RBACROLEGROUP_FORMAT: .prefix-{{deployment.shortid}}-{0}-g:

Expression Type Example output
{{rbacrolegroup.rbacfoo}} string .prefix-0fa0bb-foo-g
{{rbacrolegroup.rbacfoo.groupname}} string .prefix-0fa0bb-foo-g

Modifiers (Variables)

Variable Type Required Level Default Description
DEFAULT_AD_RESOURCEPROVIDER string Yes Variable — Identifier of the Active Directory resource provider
AD_RBACROLEGROUP_FORMAT string No ResourceProvider {0} Naming format. {0} is replaced by groupName. Supports expressions.
AD_GROUP_ROLE_OU string Yes ResourceProvider — OU path (DistinguishedName) where the group is created

Example

An RBAC role group, with a team group as member:

resources:
  - type: rbacRoleGroup
    name: rbacsysadmin
    groupName: "{{deployment.shortid}}-auditor"
    members:
      - auditor-team
  - type: computeNode
    computeType: virtualMachine
    name: vmdb
    image: win2022
    cpu: 4
    memory: 32
    domain: yourdomain.local
    config:
      - name: install-sql
        variables:
          mssql_version: sql22dev
          mssql_sysadmin_accounts: ["yourdomain\\{{rbacrolegroup.rbacsysadmin.groupname}}"]
          mssql_sqlsvc_account: "yourdomain\\{{serviceaccount.svcdb.svcname}}"
          mssql_sqlsvc_account_pass: "{{serviceaccount.svcdb.svcpassword}}"

Next: Cluster