# User access regexp based

**URL:** <https://forums.suse.com/t/user-access-regexp-based/5966>\
**Category:** Rancher 1.x\
**Created:** [March 24, 2017, 10:08pm UTC](https://forums.suse.com/t/user-access-regexp-based/5966 "2017-03-24T22:08:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![xinity](https://avatars.discourse-cdn.com/v4/letter/x/7cd45c/32.png) [@xinity](https://forums.suse.com/u/xinity)\
**Post date:** [March 24, 2017, 10:08pm UTC](https://forums.suse.com/t/user-access-regexp-based/5966/1 "2017-03-24T22:08:55Z")

</div>

Hi,

I’ve been wondering how I can give Access to all our users only to there host.

Something like user ABC can only see and use in rancher, the Server named ABC-srv.

Our user are ldap/ad based.

Is there any ways to achieve that dynamically?

Any clues appreciated 🙂

Thanks a lot,

Regards

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 24, 2017, 10:31pm UTC](https://forums.suse.com/t/user-access-regexp-based/5966/2 "2017-03-24T22:31:09Z")

</div>

Access control is at the Environment level. So you can give each user an environment and make them the only one that has access to it. Actually when they first login they will get an `theirname-default` environment setup that way if their user has no access to any other environments.

---

<div class="post-metadata">

**Author:** ![xinity](https://avatars.discourse-cdn.com/v4/letter/x/7cd45c/32.png) [@xinity](https://forums.suse.com/u/xinity)\
**Post date:** [March 25, 2017, 9:52pm UTC](https://forums.suse.com/t/user-access-regexp-based/5966/3 "2017-03-25T21:52:37Z")

</div>

Nice tips indeed!

Thanks Vincent!

Any chances to achieve something like that.:  
-A new user logs in via it’s ldap authentication.  
-an environment is dynamically created for this user  
-a specific registration endpoint is created

Thus would allow the user to add it’s desktop to the center rancher server in only one shot, without ops to do anything to make it happen.

Let me know what you think 🙂

Regards,

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 25, 2017, 10:41pm UTC](https://forums.suse.com/t/user-access-regexp-based/5966/4 "2017-03-25T22:41:05Z")

</div>

Like I said that’s basically what happens by default… When a user first logs an environment is created for them (unless they already have access to some via group memberships). They would then click add host and copy/paste/run the custom host registration command on their desktop.

---

<div class="post-metadata">

**Author:** ![xinity](https://avatars.discourse-cdn.com/v4/letter/x/7cd45c/32.png) [@xinity](https://forums.suse.com/u/xinity)\
**Post date:** [March 28, 2017, 8:00am UTC](https://forums.suse.com/t/user-access-regexp-based/5966/5 "2017-03-28T08:00:31Z")

</div>

Cool !

Thanks a lot Vincent !

One last Question : is there any way for the admin to have a “special environment” that can make us see all hosts deployed in every environment ?

Regards,

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 28, 2017, 8:31am UTC](https://forums.suse.com/t/user-access-regexp-based/5966/6 "2017-03-28T08:31:25Z")

</div>

No, but admin users can see and go into/use all the environments.

---

<div class="post-metadata">

**Author:** ![xinity](https://avatars.discourse-cdn.com/v4/letter/x/7cd45c/32.png) [@xinity](https://forums.suse.com/u/xinity)\
**Post date:** [March 28, 2017, 9:36am UTC](https://forums.suse.com/t/user-access-regexp-based/5966/7 "2017-03-28T09:36:41Z")

</div>

sad ☹

thanks a lot for your precious answers vincent
