



Feature #22441


Restrict access to puppet modules in HostGroup and Host and assign them only via Config Groups

Added by Ondřej Pražák over 6 years ago. Updated over 6 years ago.

Users, Roles and Permissions
Target version:
Fixed in Releases:
Found in Releases:


In the user environment, the Engineering is creating the puppet modules. Then the Engineering team creates a profile for hosts using Config Groups where the necessary puppet modules are included. The Operation team itself should then only select the Config Group to apply the provide and should not have access to specific puppet modules.

Therefore the user would like to have the ability to restrict access to puppet modules in HostGroup and Host to only allow a specific role to access those. Users without that role should only see the Config Groups and be able to assign those to the HostGroup or Host.

Operators should not need to care about puppet modules and also don't have the option to add specific modules to a host. Engineering is providing profiles via Config Groups that should be used to setup and configure a host (that way, things can be standarized)

Related issues 1 (1 open0 closed)

Blocked by Foreman - Feature #22439: Make permissions for editing host more granularNew01/29/2018Actions
Actions #1

Updated by Ondřej Pražák over 6 years ago

  • Blocked by Feature #22439: Make permissions for editing host more granular added
Actions #2

Updated by Ondřej Pražák over 6 years ago

  • Subject changed from Restrict access to puppet modules in HostGroup and Host and assign them only via Config Groups to Restrict access to puppet modules in HostGroup and Host and assign them only via Config Groups

This is essentially another request for granular edit_hosts permissions, this time for Puppet modules and Config Groups.

Actions #3

Updated by Ondřej Pražák over 6 years ago

  • Category set to Users, Roles and Permissions

Also available in: Atom PDF