<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Customized RBAC in cDOT 8.2.3 in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Customized-RBAC-in-cDOT-8-2-3/m-p/106637#M21938</link>
    <description>&lt;P&gt;Hello, comrades!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, our shop is relatively small, and I'm basically the only storage guy. Things are changing, though, and I need to pass off some lightweight, repeatable, and relatively low-impact duties to a handful of NOC folks. I don't want to give them the keys to the kingdom, so I want to cook up a new role for them that can do the stuff they need to do.&amp;nbsp;&lt;SPAN&gt;Specifically they'll&amp;nbsp;need to be able to run regular health checks (as our environment doesn't allow for automatic ASUP uploads), and to provision storage.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get how to create a security role in cDOT (&lt;STRONG&gt;sec login role create -role NOC -access readonly -cmddirname "cluster peer show"&amp;nbsp;&lt;/STRONG&gt;or &lt;STRONG&gt;... -access all -cmddirname "volume modify"&amp;nbsp;&lt;/STRONG&gt;and stuff like that). What I'm not sure about&amp;nbsp;whether I can allow this role to&amp;nbsp;&lt;STRONG&gt;set diag&amp;nbsp;&lt;/STRONG&gt;and run diagnostic privileged commands, and if I can, how to do it? Is it as simple as&amp;nbsp;&lt;STRONG&gt;... -access all -cmddirname "set"&lt;/STRONG&gt;? What unintended consequences and privileges, if any, would I be conferring on this role if I did that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all!&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jun 2025 04:08:25 GMT</pubDate>
    <dc:creator>SMLocke</dc:creator>
    <dc:date>2025-06-05T04:08:25Z</dc:date>
    <item>
      <title>Customized RBAC in cDOT 8.2.3</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Customized-RBAC-in-cDOT-8-2-3/m-p/106637#M21938</link>
      <description>&lt;P&gt;Hello, comrades!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, our shop is relatively small, and I'm basically the only storage guy. Things are changing, though, and I need to pass off some lightweight, repeatable, and relatively low-impact duties to a handful of NOC folks. I don't want to give them the keys to the kingdom, so I want to cook up a new role for them that can do the stuff they need to do.&amp;nbsp;&lt;SPAN&gt;Specifically they'll&amp;nbsp;need to be able to run regular health checks (as our environment doesn't allow for automatic ASUP uploads), and to provision storage.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get how to create a security role in cDOT (&lt;STRONG&gt;sec login role create -role NOC -access readonly -cmddirname "cluster peer show"&amp;nbsp;&lt;/STRONG&gt;or &lt;STRONG&gt;... -access all -cmddirname "volume modify"&amp;nbsp;&lt;/STRONG&gt;and stuff like that). What I'm not sure about&amp;nbsp;whether I can allow this role to&amp;nbsp;&lt;STRONG&gt;set diag&amp;nbsp;&lt;/STRONG&gt;and run diagnostic privileged commands, and if I can, how to do it? Is it as simple as&amp;nbsp;&lt;STRONG&gt;... -access all -cmddirname "set"&lt;/STRONG&gt;? What unintended consequences and privileges, if any, would I be conferring on this role if I did that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 04:08:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Customized-RBAC-in-cDOT-8-2-3/m-p/106637#M21938</guid>
      <dc:creator>SMLocke</dc:creator>
      <dc:date>2025-06-05T04:08:25Z</dc:date>
    </item>
  </channel>
</rss>

