<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles in Tanzu Mission Control &amp; VMware Cloud Director Discussion Board</title>
    <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2984455#M13</link>
    <description>&lt;P&gt;Sorry for the delay, I am still looking into this with the engineering team.&lt;/P&gt;
&lt;P&gt;Beyond logging in, were you able to view/edit any TMC resources when using the `&lt;SPAN&gt;Cloud Administrator` role?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Aug 2023 15:37:02 GMT</pubDate>
    <dc:creator>jeffmace</dc:creator>
    <dc:date>2023-08-29T15:37:02Z</dc:date>
    <item>
      <title>TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2982488#M4</link>
      <description>&lt;P&gt;Currently, I can login to TMC CLI in the following ways:&lt;/P&gt;
&lt;P&gt;1) Using LDAP accountswith `Cloud Administrator` role&lt;/P&gt;
&lt;P&gt;2) Using LDAP account with role `tmc:admin`&lt;/P&gt;
&lt;P&gt;3) Using local accounts `tmc-amin`, `tmc-member` or any other local accounts with role `tmc:admin` or `tmc:member` assigned to them&lt;/P&gt;
&lt;P&gt;I cannot authenticate to TMC CLI from LDAP/local accounts/groups for which I have authentication configured TMC GUI Access section. See screenshot that shows current access policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="returntrip_0-1692189441843.png" style="width: 400px;"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/103048iE30BCFFBF6A89CA2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="returntrip_0-1692189441843.png" alt="returntrip_0-1692189441843.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To me, it seems like the `tmc-admin` or `tmc-member` roles are necessary to log ont TMC CLI and subsequentially accesst the K8s API via says kubectl However, having those roles gives automatically admin access to TMC managed K8s clusters which defeats the purpose of RBAC.&lt;/P&gt;
&lt;P&gt;Am I missing something?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 13:12:00 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2982488#M4</guid>
      <dc:creator>returntrip</dc:creator>
      <dc:date>2023-08-16T13:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2984455#M13</link>
      <description>&lt;P&gt;Sorry for the delay, I am still looking into this with the engineering team.&lt;/P&gt;
&lt;P&gt;Beyond logging in, were you able to view/edit any TMC resources when using the `&lt;SPAN&gt;Cloud Administrator` role?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 15:37:02 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2984455#M13</guid>
      <dc:creator>jeffmace</dc:creator>
      <dc:date>2023-08-29T15:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2984458#M15</link>
      <description>&lt;P&gt;I could manage the cluster (i.e.: kubectl get nodes, get pods etc)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 15:54:02 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2984458#M15</guid>
      <dc:creator>returntrip</dc:creator>
      <dc:date>2023-08-29T15:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2986527#M18</link>
      <description>&lt;P&gt;We are still looking into this but I want to make sure I understand what you would like to achieve.&lt;/P&gt;
&lt;P&gt;Are you trying to use the "Cloud Administrator" role to grant access to the TMC-SM API/GUI so they can define policies/packages/etc in TMC-SM?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 12:25:03 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2986527#M18</guid>
      <dc:creator>jeffmace</dc:creator>
      <dc:date>2023-09-13T12:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2986531#M19</link>
      <description>&lt;P&gt;My TMC Local is not working as I am waiting for a newer version compatible with CSE 4.1. But I was trying to use Acces Roles to manage/limit K8s API access (e.g: limit certain users to certain namespaces)&lt;/P&gt;
&lt;P&gt;What I noticed was that you need&amp;nbsp; either&amp;nbsp;&lt;SPAN&gt;tmc-admin` or `tmc-member`&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;roles to log onto TMC CLI (the command line interface for TMC), which allows you to access the k8s API via kubectl. Having &amp;nbsp;tmc-admin` or `tmc-member` roles automatically gives full (admin) access to TMC managed K8s clusters and I am therefore unable to limit certain users or groups (i.e.: useer `johndoe` should only be able to list namesapces fro k8s cluster xyz).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I hope this makes sense. If not, lets wait for a new version of TMC that supports CSE 4.1. Will reinstall and can get into a meeting.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 12:36:51 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2986531#M19</guid>
      <dc:creator>returntrip</dc:creator>
      <dc:date>2023-09-13T12:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2986532#M20</link>
      <description>&lt;P&gt;Yes, that makes sense. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 12:39:04 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2986532#M20</guid>
      <dc:creator>jeffmace</dc:creator>
      <dc:date>2023-09-13T12:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: TMC Managed K8s Cluster - CLI  authentication and Access Roles</title>
      <link>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2988389#M21</link>
      <description>&lt;P&gt;We've been looking into this and can confirm you will be able to use roles other than 'tmc:admin' or 'tmc:member' to give access to specific resources. I believe this scenario would've worked if you had added the 'Organization Administrator' group to the 'organization.credential.view' role binding or some other 'organization.*' role.&lt;/P&gt;
&lt;P&gt;Please try this after we GA a release with support for CSE 4.1 and let us know if you run into issues.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 17:35:33 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Tanzu-Mission-Control-VMware/TMC-Managed-K8s-Cluster-CLI-authentication-and-Access-Roles/m-p/2988389#M21</guid>
      <dc:creator>jeffmace</dc:creator>
      <dc:date>2023-09-26T17:35:33Z</dc:date>
    </item>
  </channel>
</rss>

