VMware Solutions Discussions

ONTAP Tools for VMware vSphere - service account permissions

prcpa8w3p
1,658 Views

Setting up OTV using a service account and per our internal security team best practices, they won't allow us to give the service account administrator rights into vCenter. 

 

What are the granular permissions that we can grant to the service account that'll still allow us to both successfully install and manage OTV?

 

Configuration: 

vCenter: 8.0 Update 2

ONTAP: 9.13.1Px

OTV: 9.13P1

6 REPLIES 6

prcpa8w3p
1,429 Views

Hi All - any update on this?

ChanceBingen
1,379 Views

I haven't tried, but according to this two key things you need are access to the ExtensionManager.registerExtension(), updateExtension(), and I'm also guessing you will want to have access to the unregisterExtension() methods collectively.

Connect the extension to vCenter Server (vmware.com)

Unregister the extension from vCenter Server (vmware.com)

 

When you register the plugin, it also creates roles so you need to have rights to do that too.

 

When you actually use the product, it operates as the logged in user. So creating datastores and such are inherited from that.

 

When I look in the vCenter GUI, I can see these. Give it a try and let us know how it goes.

 

ChanceBingen_0-1719424324069.png

 

ChanceBingen
1,379 Views

prcpa8w3p
1,164 Views

@ChanceBingen  - thank you for looking into this. We keep coming across the following NetApp KBA which we don't currently have access to - is it possible for you to share the contents?

https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/Virtual_Storage_Console_for_VMware_vSphere/How_to_configure_RBAC_for_Virtual_St...

ChanceBingen
1,158 Views

Looks like that KB has been archived and replaced with this one: ONTAP Tools for VMware vSphere: RBAC Configuration - NetApp Knowledge Base

prcpa8w3p
1,128 Views

@ChanceBingen - ty sir, appreciate it. We're going to try it out in our test/engineering labs

Public