The HPE GreenLake for Authorization API provides a unified way to manage the authorization function for HPE GreenLake cloud.
- HPE GreenLake for Authorization API
HPE GreenLake for Authorization API (1.0.0-beta)
https://global.api.greenlake.hpe.com/
https://developer.greenlake.hpe.com/_mock/docs/greenlake/services/authorization/public/openapi/authz-v1beta1/external-authz-v2-config/
Roles
Roles are created in a Workspace, typically by an IAM administrator. They may be created by a Resource Provider (RP) if the RP has been granted the required privileges in the Workspace.
Requirements
- Roles must include at least one inline permission.
- There is a max limit of 100 Roles per workspace (in addition to the global predefined roles).
Role Assignments
Role assignments are composed of three pieces (principal, role, and scope). Role assigments associate a user, group, or service (principal) with a specific role (along with its permissions) at a particular scope (a resource or group of resources) to grant them access and specify their responsibilities within HPE GreenLake.
Note: There is a maximum limit of 50 role assignments per user per workspace.