The roles provide RBAC. Each role has a name and 1 or more groups (local, ldap or azuread). The admin and public rol is mandatory. Since version 4.0.11 you can also add users (local, ldap or azuread). Since version 5.0.8 options are introduced to add specific role-options.
showDesigner: The user can see the designer
showSettings: The user can see the settings page
showDebugButtons: The user can see the debug buttons on a form
showExtravars: The user can see the extravars on a form
showLogs: The user can see the logs page
showJobs: The user can see the jobs page. Default true.
showArtifacts: The user can see the artifacts an AWX job returns. Default true.
extendedTokenExpiration: The user can request a token with a longer expiration time (for coding api purposes for example)
showAllJobLogs: The user can see all job logs (not only his own) (Added in 5.0.9)
allowLogin: The user can login.
allowBackupOps: The user can perform database operations, such as backup and restore.
allowVerboseMode: The user can enable verbose mode on ansible forms.
allowJobRelaunch: The user can relaunch jobs with pre-filled form data from previous submissions.
allowScheduledJobs: The user can create and manage scheduled jobs (recurring cron or one-time). Default for admins only. Grant it only to roles you would trust as admins: every user with this option sees and can change all schedules, not only their own, and a schedule runs with admin rights, for any form. (Added in 6.1.5)
allowStoredJobs: The user can store and load job data for later use. (Added in 6.1.5)
allowPlannedJobs: The user can schedule jobs to run at a specific time. (Added in 6.1.5)
allowChat: The user can use the chat assistant (when it is enabled). Default true. (Added in 6.5.0)
When options are not set, the admin role will have all options. When options are set on the public role, they will have the lowest precedence and can be used as default options for all roles. You can add options on role level, which will override the public role options.
The allowLogin option is different, that is for the backend. By default everyone can login. You can set it to false on public and then enable on the roles you want to give access. Watch out you don’t lock yourself out.
Examples:
1) Roles
roles:-name:admin# is mandatorygroups:-local/admins-ldap/Domain Admins-azuread/Domain Admins-name:operatorgroups:-local/operator-name:architectgroups:-local/architectoptions:showDesigner:true# architects can see the designershowLogs:true# architects can see the logsallowJobRelaunch:true# architects can relaunch jobs with pre-filled data-name:demogroups:-local/demo-name:usersonlyusers:-local/myuser-name:public# is mandatorygroups:[]options:showDebugButtons:true# everyone can see the debug buttonsshowExtraVars:true# everyone can see the extravars
Role object
Each entry of the roles list:
A role allows RBAC. Each role has 1 or more groups (local or ldap). Except the public role, which has no groups. The public and admin roles are mandatory.
Attribute
Comments
name string / required / unique
The name of the role alphanumeric + dash + underscore + space
The name of a role has to be unique. The public and admin roles are mandatory.
groups array / required
Groups A group (local, ldap or azuread)
A list of groups. They must be in the format of local/groupname or ldap/groupname or azuread/groupname
users array / required added in version 4.0.10
User A user (local, ldap or azuread)
A list of local or ldap users. They must be in the format of local/username or ldap/username or azuread/username
options object added in version 5.0.8
Role options Key value pairs
Since version 5.0.8 you can add specific role options. The options are used to enable or disable certain features for a role. The options are:
showDesigner: The user can see the designer
showSettings: The user can see the settings page
showDebugButtons: The user can see the debug buttons on a form
showExtravars: The user can see the extravars on a form
showLogs: The user can see the logs page
showJobs: The user can see the jobs page. Default true.
showArtifacts: The user can see the artifacts an AWX job returns. Default true.
extendedTokenExpiration: The user can request a token with a longer expiration time (for coding api purposes for example)
showAllJobLogs: The user can see all job logs (not only his own) (Added in 5.0.9)
allowLogin: The user can login.
allowBackupOps: The user can perform database operations, such as backup and restore.
allowVerboseMode: The user can enable verbose mode on ansible forms.
allowJobRelaunch: The user can relaunch jobs with pre-filled form data from previous submissions.
allowScheduledJobs: The user can create and manage scheduled jobs (recurring cron or one-time). Default for admins only. Grant it only to roles you would trust as admins: every user with this option sees and can change all schedules, not only their own, and a schedule runs with admin rights, for any form. (Added in 6.1.5)
allowStoredJobs: The user can store and load job data for later use. (Added in 6.1.5)
allowPlannedJobs: The user can schedule jobs to run at a specific time. (Added in 6.1.5)
allowChat: The user can use the chat assistant (when it is enabled). Default true. (Added in 6.5.0)
When options are not set, the admin role will have all options. When options are set on the public role, they will have the lowest precedence and can be used as default options for all roles. You can add options on role level, which will override the public role options.
Examples
1) Roles
roles:-name:admin# is mandatorygroups:-local/admins-ldap/Domain Admins-name:operatorgroups:-local/operatorusers:-azuread/mike-name:architectgroups:-local/architectoptions:showDesigner:true# architects can see the designershowLogs:true# architects can see the logs-name:demogroups:-local/demo-name:public# is mandatorygroups:[]options:showDebugButtons:true# everyone can see the debug buttonsshowExtraVars:true# everyone can see the extravars