# Authorisation on namespaced resource

**URL:** <https://forums.suse.com/t/authorisation-on-namespaced-resource/37516>\
**Category:** SUSE Rancher Prime\
**Created:** [April 6, 2022, 8:50pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516 "2022-04-06T20:50:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [April 6, 2022, 8:50pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/1 "2022-04-06T20:50:10Z")

</div>

I play around with rancher dashboard, but really lost with user and permissions setting.  
I read somewhere that in rancher, users permissions are set for cluster or project. However if I wanna set user permissions on particular resource in a namespace, is that possible in rancher? As I can see that k8s RBAC can do this by defining role and rolebinding. But I could not find anywhere to bind a user to k8s roles, if this possible, did I miss somehting?

---

<div class="post-metadata">

**Author:** ![wcoateRR](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/wcoaterr/32/8144_2.png) [@wcoateRR](https://forums.suse.com/u/wcoateRR)\
**Post date:** [April 6, 2022, 9:06pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/2 "2022-04-06T21:06:52Z")

</div>

You can use the normal Kubernetes RBAC in Rancher to the best of my knowledge, so you should be able to do the same kubectl commands to make it work in a Rancher downstream (or local I guess).

---

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [April 7, 2022, 7:06am UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/4 "2022-04-07T07:06:23Z")

</div>

So life is back to plain but stable kubectl. No fancy UI for this. Anyone have a nice walkthrough for this? for example, how to find out service account (if there is one) of the user?

---

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [April 7, 2022, 7:07am UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/5 "2022-04-07T07:07:18Z")

</div>

@BedamatiMohanty Lost even further 😅

---

<div class="post-metadata">

**Author:** ![wcoateRR](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/wcoaterr/32/8144_2.png) [@wcoateRR](https://forums.suse.com/u/wcoateRR)\
**Post date:** [April 7, 2022, 1:38pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/6 "2022-04-07T13:38:52Z")

</div>

I don’t have any walkthroughs, haven’t started mucking with it much myself. If you drive down through the cluster explorer there is an RBAC section that I think you can do all this through the UI, but I’m not sure if it’ll save you much time or effort since it’s kinda’ buried so may be more “here’s a GUI form for the CLI thing” rather than offering much help, though once again, I haven’t looked.

---

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [April 7, 2022, 2:01pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/7 "2022-04-07T14:01:47Z")

</div>

```auto
apiVersion: management.cattle.io/v3
description: user1
displayName: user1
enabled: true
kind: User
metadata:
  annotations:
    field.cattle.io/creatorId: user-hrfkn
    lifecycle.cattle.io/create.mgmt-auth-users-controller: "true"
  finalizers:
  - controller.cattle.io/mgmt-auth-users-controller
  generateName: u-
  generation: 3
  labels:
    cattle.io/creator: norman
  name: u-vg5kr
  resourceVersion: "2014100"
  uid: bf2d3be4-11b5-4912-a577-f85a55bea492
password: $2a$10$pGNE8/0IQ.KGpcf6DpOnAuDMuHXTKAzd2JbPD6J88h14ro3lBXoWq
principalIds:
- local://u-vg5kr
spec: {}
username: user1

```

The problem is that clusterrolebinding/rolebinding bind SA to role. Rancher user account is not a SA, who It can be converted into an SA and use in rolebindings?

---

<div class="post-metadata">

**Author:** ![liyi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/liyi/32/4609_2.png) [@liyi](https://forums.suse.com/u/liyi)\
**Post date:** [April 7, 2022, 2:06pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/8 "2022-04-07T14:06:02Z")

</div>

Oh， user can also used as sa, right?

---

<div class="post-metadata">

**Author:** ![wcoateRR](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/wcoaterr/32/8144_2.png) [@wcoateRR](https://forums.suse.com/u/wcoateRR)\
**Post date:** [April 7, 2022, 2:11pm UTC](https://forums.suse.com/t/authorisation-on-namespaced-resource/37516/9 "2022-04-07T14:11:58Z")

</div>

Unsure as I haven’t really done anything with this. There do end up being more Rancher folks looking at questions on Slack than here, so you might try asking there if you don’t get anything on your debugging or someone popping in here.
