RbacRoleGroup¶
The RbacRoleGroup resource creates Active Directory Global security groups. These are typically used for role-based access control — granting groups of users specific permissions on resources.
Structure¶
- type: RbacRoleGroup
name: roleauditor # unique identifier within the RGT
groupName: "{{deployment.shortid}}-auditor" # AD group name (supports expressions)
members: # optional, members to add to the group
- user-foo # reference users or groups within the same domain
| Key | Required | Description |
|---|---|---|
type |
Yes | Must be RbacRoleGroup |
name |
Yes | Unique identifier within the RGT (used in expressions) |
groupName |
Yes | The actual AD group name. Supports expressions. |
members |
No | List of users or groups to add as members. Supports expressions. No domain needed. Same-domain membership only due to global security group. |
Naming Format¶
The final AD group name is determined by combining the AD_RBACROLEGROUP_FORMAT variable with groupName:
- Format variable:
AD_RBACROLEGROUP_FORMATuses{0}as a placeholder for thegroupNamevalue - Default:
{0}(the groupName is used as-is) - Example: If
AD_RBACROLEGROUP_FORMATis.{{tenant.name}}-{{deployment.shortid}}-{0}-gandgroupNameisfoo, the final name is.acme-0fa0bb-foo-g
The group is created in the AD_GROUP_ROLE_OU organizational unit.
Reference Format¶
Use {{rbacrolegroup.<name>.<property>}} to reference an RBAC group in expressions.
Given a group with name: rbacfoo, groupName: foo, and AD_RBACROLEGROUP_FORMAT: .prefix-{{deployment.shortid}}-{0}-g:
| Expression | Type | Example output |
|---|---|---|
{{rbacrolegroup.rbacfoo}} |
string | .prefix-0fa0bb-foo-g |
{{rbacrolegroup.rbacfoo.groupname}} |
string | .prefix-0fa0bb-foo-g |
Modifiers (Variables)¶
| Variable | Type | Required | Level | Default | Description |
|---|---|---|---|---|---|
DEFAULT_AD_RESOURCEPROVIDER |
string | Yes | Variable | — | Identifier of the Active Directory resource provider |
AD_RBACROLEGROUP_FORMAT |
string | No | ResourceProvider | {0} |
Naming format. {0} is replaced by groupName. Supports expressions. |
AD_GROUP_ROLE_OU |
string | Yes | ResourceProvider | — | OU path (DistinguishedName) where the group is created |
Example¶
An RBAC role group, with a team group as member:
resources:
- type: rbacRoleGroup
name: rbacsysadmin
groupName: "{{deployment.shortid}}-auditor"
members:
- auditor-team
- type: computeNode
computeType: virtualMachine
name: vmdb
image: win2022
cpu: 4
memory: 32
domain: yourdomain.local
config:
- name: install-sql
variables:
mssql_version: sql22dev
mssql_sysadmin_accounts: ["yourdomain\\{{rbacrolegroup.rbacsysadmin.groupname}}"]
mssql_sqlsvc_account: "yourdomain\\{{serviceaccount.svcdb.svcname}}"
mssql_sqlsvc_account_pass: "{{serviceaccount.svcdb.svcpassword}}"
Next: Cluster