<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Astra Trident user access permissions - limitAggregateUsage option in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Astra-Trident-user-access-permissions-limitAggregateUsage-option/m-p/443113#M41998</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was trying to use the&amp;nbsp;limitAggregateUsage option to restrict aggregate usage by Trident. Initially, Trident was using a non-admin user account, and the option was giving me an error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So digging in the docs I found this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"If you use the limitAggregateUsage parameter, cluster admin permissions are required. When using Amazon FSx for NetApp ONTAP with Astra Trident, the limitAggregateUsage parameter will not work with the vsadmin and fsxadmin user accounts. The configuration operation will fail if you specify this parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While it is possible to create a more restrictive role within ONTAP that a Trident driver can use, we don’t recommend it. Most new releases of Trident will call additional APIs that would have to be accounted for, making upgrades difficult and error-prone.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you guys think of it? Customer was a little concerned in giving an admin account to their kubernetes cluster admin. Have anyone had this concern or used this options (limitAggregateUsage)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Pedro Rocha&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:51:05 GMT</pubDate>
    <dc:creator>pedro_rocha</dc:creator>
    <dc:date>2025-06-04T09:51:05Z</dc:date>
    <item>
      <title>Astra Trident user access permissions - limitAggregateUsage option</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Astra-Trident-user-access-permissions-limitAggregateUsage-option/m-p/443113#M41998</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was trying to use the&amp;nbsp;limitAggregateUsage option to restrict aggregate usage by Trident. Initially, Trident was using a non-admin user account, and the option was giving me an error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So digging in the docs I found this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"If you use the limitAggregateUsage parameter, cluster admin permissions are required. When using Amazon FSx for NetApp ONTAP with Astra Trident, the limitAggregateUsage parameter will not work with the vsadmin and fsxadmin user accounts. The configuration operation will fail if you specify this parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While it is possible to create a more restrictive role within ONTAP that a Trident driver can use, we don’t recommend it. Most new releases of Trident will call additional APIs that would have to be accounted for, making upgrades difficult and error-prone.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you guys think of it? Customer was a little concerned in giving an admin account to their kubernetes cluster admin. Have anyone had this concern or used this options (limitAggregateUsage)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Pedro Rocha&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:51:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Astra-Trident-user-access-permissions-limitAggregateUsage-option/m-p/443113#M41998</guid>
      <dc:creator>pedro_rocha</dc:creator>
      <dc:date>2025-06-04T09:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Astra Trident user access permissions - limitAggregateUsage option</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Astra-Trident-user-access-permissions-limitAggregateUsage-option/m-p/443240#M42026</link>
      <description>&lt;P&gt;I see your (valid) point. I also read the documentation and it says exactly what you mentioned. I think the reason could be b'cos of the fact that 'vsadmin' (pre-defined SVM admin roles) are basically limited to 'volume' only, they have no control over 'aggr'. Only 'Cluster Admin' can deal with 'aggr' related attributes, or a custom account of more restrictive role. Interestingly it discourages to use it, and this may be due to fact that, may be there is no clear visibility of what API (additional) requests are made to the Storage, which means it can be a very laborious task to keep adding the -api* to the custom role until the error is gone.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 15:06:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Astra-Trident-user-access-permissions-limitAggregateUsage-option/m-p/443240#M42026</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-04-06T15:06:29Z</dc:date>
    </item>
  </channel>
</rss>

