Roles

Map users and groups to roles, and set what each role may do.

  1. The roles attribute
  2. Role object

The roles attribute

The top-level roles list of config.yaml:

Attribute Comments
roles
array

Roles
🔗 valid role object

The roles provide RBAC. Each role has a name and 1 or more groups (local, ldap or azuread). The admin and public rol is mandatory.
Since version 4.0.11 you can also add users (local, ldap or azuread).
Since version 5.0.8 options are introduced to add specific role-options.

  • showDesigner: The user can see the designer
  • showSettings: The user can see the settings page
  • showDebugButtons: The user can see the debug buttons on a form
  • showExtravars: The user can see the extravars on a form
  • showLogs: The user can see the logs page
  • showJobs: The user can see the jobs page. Default true.
  • showArtifacts: The user can see the artifacts an AWX job returns. Default true.
  • extendedTokenExpiration: The user can request a token with a longer expiration time (for coding api purposes for example)
  • showAllJobLogs: The user can see all job logs (not only his own) (Added in 5.0.9)
  • allowLogin: The user can login.
  • allowBackupOps: The user can perform database operations, such as backup and restore.
  • allowVerboseMode: The user can enable verbose mode on ansible forms.
  • allowJobRelaunch: The user can relaunch jobs with pre-filled form data from previous submissions.
  • allowScheduledJobs: The user can create and manage scheduled jobs (recurring cron or one-time). Default for admins only. Grant it only to roles you would trust as admins: every user with this option sees and can change all schedules, not only their own, and a schedule runs with admin rights, for any form. (Added in 6.1.5)
  • allowStoredJobs: The user can store and load job data for later use. (Added in 6.1.5)
  • allowPlannedJobs: The user can schedule jobs to run at a specific time. (Added in 6.1.5)
  • allowChat: The user can use the chat assistant (when it is enabled). Default true. (Added in 6.5.0)

When options are not set, the admin role will have all options.
When options are set on the public role, they will have the lowest precedence and can be used as default options for all roles.
You can add options on role level, which will override the public role options.

The allowLogin option is different, that is for the backend. By default everyone can login.
You can set it to false on public and then enable on the roles you want to give access. Watch out you don’t lock yourself out.

Examples:

1) Roles

roles:
- name: admin        # is mandatory
  groups:
  - local/admins
  - ldap/Domain Admins
  - azuread/Domain Admins
- name: operator
  groups:
  - local/operator
- name: architect
  groups:
  - local/architect
  options:
    showDesigner: true      # architects can see the designer
    showLogs: true          # architects can see the logs
    allowJobRelaunch: true  # architects can relaunch jobs with pre-filled data
- name: demo
  groups:
  - local/demo
- name: usersonly
  users:
  - local/myuser
- name: public        # is mandatory
  groups: []  
  options:
    showDebugButtons: true  # everyone can see the debug buttons
    showExtraVars: true     # everyone can see the extravars

Role object

Each entry of the roles list:

A role allows RBAC. Each role has 1 or more groups (local or ldap). Except the public role, which has no groups.
The public and admin roles are mandatory.

Attribute Comments
name
string / required / unique

The name of the role
alphanumeric + dash + underscore + space

The name of a role has to be unique. The public and admin roles are mandatory.

groups
array / required

Groups
A group (local, ldap or azuread)

A list of groups. They must be in the format of local/groupname or ldap/groupname or azuread/groupname

users
array / required
added in version 4.0.10

User
A user (local, ldap or azuread)

A list of local or ldap users. They must be in the format of local/username or ldap/username or azuread/username

options
object
added in version 5.0.8

Role options
Key value pairs

Since version 5.0.8 you can add specific role options. The options are used to enable or disable certain features for a role.
The options are:

  • showDesigner: The user can see the designer
  • showSettings: The user can see the settings page
  • showDebugButtons: The user can see the debug buttons on a form
  • showExtravars: The user can see the extravars on a form
  • showLogs: The user can see the logs page
  • showJobs: The user can see the jobs page. Default true.
  • showArtifacts: The user can see the artifacts an AWX job returns. Default true.
  • extendedTokenExpiration: The user can request a token with a longer expiration time (for coding api purposes for example)
  • showAllJobLogs: The user can see all job logs (not only his own) (Added in 5.0.9)
  • allowLogin: The user can login.
  • allowBackupOps: The user can perform database operations, such as backup and restore.
  • allowVerboseMode: The user can enable verbose mode on ansible forms.
  • allowJobRelaunch: The user can relaunch jobs with pre-filled form data from previous submissions.
  • allowScheduledJobs: The user can create and manage scheduled jobs (recurring cron or one-time). Default for admins only. Grant it only to roles you would trust as admins: every user with this option sees and can change all schedules, not only their own, and a schedule runs with admin rights, for any form. (Added in 6.1.5)
  • allowStoredJobs: The user can store and load job data for later use. (Added in 6.1.5)
  • allowPlannedJobs: The user can schedule jobs to run at a specific time. (Added in 6.1.5)
  • allowChat: The user can use the chat assistant (when it is enabled). Default true. (Added in 6.5.0)

When options are not set, the admin role will have all options.
When options are set on the public role, they will have the lowest precedence and can be used as default options for all roles.
You can add options on role level, which will override the public role options.

Examples

1) Roles

roles:
- name: admin        # is mandatory
  groups:
  - local/admins
  - ldap/Domain Admins
- name: operator
  groups:
  - local/operator
  users:
  - azuread/mike
- name: architect
  groups:
  - local/architect
  options:
    showDesigner: true # architects can see the designer
    showLogs: true     # architects can see the logs
- name: demo
  groups:
  - local/demo
- name: public        # is mandatory
  groups: []  
  options:
    showDebugButtons: true  # everyone can see the debug buttons
    showExtraVars: true     # everyone can see the extravars              

Copyright © 2023-2026 AnsibleForms. All rights reserved.

This site uses Just the Docs, a documentation theme for Jekyll.