mirror of
https://github.com/gravitational/teleport
synced 2024-10-19 16:53:57 +00:00
allow the default editor role to create nodes (#29763)
This commit is contained in:
parent
db08adca8e
commit
1ca745ca0e
|
@ -161,6 +161,7 @@ func NewPresetEditorRole() types.Role {
|
|||
types.NewRule(types.KindBilling, RW()),
|
||||
types.NewRule(types.KindClusterAlert, RW()),
|
||||
types.NewRule(types.KindAccessList, RW()),
|
||||
types.NewRule(types.KindNode, RW()),
|
||||
// Please see defaultAllowRules when adding a new rule.
|
||||
},
|
||||
},
|
||||
|
@ -407,6 +408,7 @@ func defaultAllowRules() map[string][]types.Rule {
|
|||
types.NewRule(types.KindBilling, RW()),
|
||||
types.NewRule(types.KindInstance, RO()),
|
||||
types.NewRule(types.KindAssistant, append(RW(), types.VerbUse)),
|
||||
types.NewRule(types.KindNode, RW()),
|
||||
},
|
||||
teleport.PresetAccessRoleName: {
|
||||
types.NewRule(types.KindInstance, RO()),
|
||||
|
|
Loading…
Reference in a new issue