Skip to main content

Managing Capability Sets in CloudShell

Understanding Capability Sets in CloudShell

In Quali's CloudShell environment, user permissions are traditionally governed by roles assigned to user groups, such as system admins, domain admins, regular users, and external users. Each role comes with predefined permissions within specific domains.

Role-Based Permissions

By default, roles dictate what actions users can perform within CloudShell. These permissions include accessing settings, managing execution servers, handling categories, viewing sandbox data, managing users and permissions, modifying resources and services within blueprints and sandboxes, and more.

Introducing Capability Sets

However, to provide more granular control over permissions, CloudShell introduces Capability Sets. These sets allow administrators to define specific capabilities that either ALLOW or DENY actions beyond what roles permit. This flexibility enables organizations to tailor access rights precisely to their operational needs.

Managing Capability Sets

Capability Sets can be managed through both the CloudShell API and the CloudShell Portal. In the portal, administrators navigate to MANAGE > Permissions to create new capability sets. Here, they can associate specific capabilities with these sets, specifying whether each capability is allowed or denied.

Associating Capability Sets with User Groups

Administrators can then associate these Capability Sets with user groups. If multiple Capability Sets apply to a user group, the system prioritizes the most permissive settings for each capability.

Available Capabilities

In CloudShell Portal, each capability's description is shown as a tooltip when you build a capability set.

CapabilityDescription
VIEW_SETTINGSAccess to the Manage page in CloudShell Portal.
VIEW_EXECUTION_SERVERSAccess to Manage/Execution Servers, to monitor execution servers.
VIEW_CATEGORIESAccess to Manage/Categories.
VIEW_SANDBOX_DATAAccess to sandbox data in CloudShell Portal.
MANAGE_USERS_PERMISSIONSAbility to manage Capability Sets and Roles.
ADD_REMOVE_BLUEPRINT_RESOURCEAdd or remove resources from blueprints.
ADD_REMOVE_SANDBOX_RESOURCEAdd or remove resources from sandboxes.
ADD_REMOVE_BLUEPRINT_ABSTRACT_RESOURCEModify abstract resources in blueprints.
ADD_REMOVE_SANDBOX_ABSTRACT_RESOURCEModify abstract resources in sandboxes.
ADD_REMOVE_BLUEPRINT_SERVICEAdd or remove services from blueprints.
ADD_REMOVE_SANDBOX_SERVICEAdd or remove services from sandboxes.
ADD_REMOVE_SANDBOX_ROUTE_CONNECTIONAdd or remove routes in sandboxes.
SHARE_UNSHARE_SANDBOX_RESOURCEShare or unshare resources in sandboxes.
UNSOLVE_SANDBOX_ABSTRACTModify abstract matches in sandboxes.
MOVE_RESOURCEMove sub-resources to a different resource, or change the resource path.
SET_SANDBOX_START_TIMESet the start time for sandboxes.
SET_SANDBOX_END_TIMESet the end time for sandboxes.
UPDATE_WORK_ORDERMake changes to work orders.
VIEW_WORK_ORDERView work orders within sandboxes.

Conclusion

Capability Sets in CloudShell provide a powerful tool for fine-tuning user permissions, ensuring that organizations can manage access rights precisely according to their operational requirements. By allowing specific overrides to role-based permissions, Capability Sets empower administrators to tailor operations to their organization's needs.