Chef 360 Platform managed roles
System-defined roles are defined and managed by Chef 360 Platform and can’t be modified by users. These roles are associated with system-defined-policies, which allow users to perform all default actions.
Chef 360 Platform has the following system-defined roles.
courier-admin
The courier-admin role provides full administrative access to Chef Courier. With the courier-admin role, you have permission to:
- Create, run, and manage all Courier jobs in the organization.
- View job run details.
The courier-admin role has the following Chef 360 Platform managed policies:
- courier-manage-courier-jobs
- courier-manage-global-exceptions
- courier-track-courier-jobs
- manage-tags
- node-management-manage-node-filters
- node-management-manage-saved-lists
- node-specific-details
- self-manager-policy
- log-service-self-policy
courier-operator
The courier-operator role allows users to execute Chef Courier jobs on nodes and perform self actions.
The courier-operator role has the following Chef 360 Platform managed policies:
- courier-manage-courier-jobs
- courier-manage-global-exceptions
- courier-track-courier-jobs
- manage-tags
- node-management-manage-node-filters
- node-management-manage-saved-lists
- node-specific-details
- log-service-self-policy
dsm-admin
With the dsm-admin role, you have permission to:
- View and manage DSM nodes.
- Manage DSM objects such as cookbooks, roles, data bags, environments, and clients.
The dsm-admin role has the following Chef 360 Platform managed policies:
- dsm-manage-objects
- dsm-manage-clients
- dsm-manage-user-keys
- node-accounts-viewer-policy
- self-manager-policy
- log-service-self-policy
dsm-viewer
The dsm-viewer role is similar to the dsm-admin role but only provides view access. With the dsm-viewer role, you can view DSM nodes and objects but can’t edit or change them.
The dsm-viewer role has the following Chef 360 Platform managed policies:
node-manager
The node-manager role has the minimum privileges required to grant a user the ability to manage nodes and skills on nodes.
The node-manager role has the following Chef 360 Platform managed policies:
- manage-node-cohorts
- manage-override-settings
- manage-skill-assembly
- manage-skill-definitions
- manage-tags
- node-enrollment
- node-management-manage-node-filters
- node-management-manage-saved-lists
- node-specific-details
- self-manager-policy
- application_key_access_policy
- node_approve_policy
- node-archive-policy
- log-service-self-policy
org-admin
The org-admin role grants privileges to manage user-defined roles and policies, user related actions, user’s API tokens, and node related actions.
The org-admin role has the following Chef 360 Platform managed policies:
- authz-policy-role-management
- node-accounts-admin-policy
- node-accounts-viewer-policy
- self-manager-policy
- user-accounts-manage-policy
- user-accounts-manage-api-token-policy
- user-accounts-manage-users-policy
- log-service-self-policy
org-viewer
The org-viewer role has the minimum privileges required to perform node-accounts node view actions and self actions according to the policies mentioned below.
The org-viewer role is the default role assigned to users when they’re added to an organization.
The org-viewer role has the following Chef 360 Platform managed policies:
tenant-admin
The system tenant-admin role grants privileges to perform user related actions, manage self actions, perform organization related operations, license management and license usage.
The tenant-admin role has the following Chef 360 Platform managed policies: