mirror of
https://github.com/qdrant/landing_page.git
synced 2026-09-26 22:48:30 +02:00
Merge pull request #1495 from qdrant/rbac-documentation
Add RBAC documentation
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
---
|
||||
title: Cloud RBAC
|
||||
weight: 16
|
||||
partition: cloud
|
||||
---
|
||||
|
||||
# Cloud RBAC - Early Access
|
||||
|
||||
## About Cloud RBAC
|
||||
|
||||
Qdrant Cloud enables you to manage permissions for your cloud resources with greater precision within the Qdrant Cloud console. This feature ensures that only authorized users have access to sensitive data and capabilities, covering the following areas:
|
||||
|
||||
- Billing
|
||||
- Identity and Access Management
|
||||
- Clusters*
|
||||
- Hybrid Cloud
|
||||
- Account Configuration
|
||||
|
||||
*Note: Current permissions control access to ALL clusters. Per Cluster permissions will be in a future release.*
|
||||
|
||||
> 💡 You can access this in **Access Management > User & Role Management** *if enabled.*
|
||||
|
||||
### How can I participate in the Early Access program for Cloud RBAC?
|
||||
|
||||
Customers who are interested should [register your interest](https://share-eu1.hsforms.com/1H5vI2Xx6TbCjwfyARUwQaA2b46ng).
|
||||
|
||||
Check out our [Early Access FAQ](/documentation/cloud-rbac/early-access-faq/) for more information.
|
||||
|
||||
## Guides
|
||||
|
||||
- [Role Management](/documentation/cloud-rbac/role-management/)
|
||||
- [User Management](/documentation/cloud-rbac/user-management/)
|
||||
|
||||
## Reference
|
||||
|
||||
- [Permission List](/documentation/cloud-rbac/permission-reference/)
|
||||
@@ -0,0 +1,65 @@
|
||||
---
|
||||
title: Early Access FAQ
|
||||
weight: 4
|
||||
---
|
||||
|
||||
|
||||
# Early Access FAQ
|
||||
|
||||
## 1. What is the difference between Cloud RBAC and Database API Keys?
|
||||
|
||||
Cloud RBAC covers permissions within the Qdrant Cloud console such as Billing and Backups, while Database API Keys deliver programmatic credentials with access control at a cluster level, including per-collection permissions.
|
||||
|
||||
## 2. Will my existing operations be disrupted?
|
||||
|
||||
We are committed to minimizing disruption during the rollout process.
|
||||
|
||||
## 3. Will this change how I interact with my cloud resources?
|
||||
|
||||
Initially, you may need to adjust your workflows in the cloud console if you restrict permissions for users. However, our phased rollout approach is designed to minimize disruption.
|
||||
|
||||
Existing Database API Keys for direct cluster access will not be affected, as Cloud RBAC only affects the capabilities and resources of the cloud console itself not the cluster.
|
||||
|
||||
## 4. I am currently an admin in another account, will I lose access once this is enabled?
|
||||
|
||||
No, for existing users already invited to another account, we will not be changing any permissions as you have already been granted Admin privileges. It will be up to the account owner and users who also have permission to configure RBAC to apply new permissions.
|
||||
|
||||
Moving forward, any new users invited to an account will be assigned the base role meaning they will not automatically become admins like today.
|
||||
|
||||
Admins will be also be able to assign pre-configured roles to a user when inviting them as part of the overhauled Invitations and User Management UI.
|
||||
|
||||
## 5. I have SSO, will I be able to use Cloud RBAC?
|
||||
|
||||
Cloud RBAC treats all users the same, regardless of authentication method.
|
||||
|
||||
## 6. How can I participate in the Early Access program for Cloud RBAC?
|
||||
|
||||
Customers who are interested should [register your interest](https://share-eu1.hsforms.com/1H5vI2Xx6TbCjwfyARUwQaA2b46ng).
|
||||
|
||||
## 7. I use Hybrid Cloud, how will this feature affect me?
|
||||
|
||||
Cloud RBAC is focused on the Cloud Interface itself, this means for Hybrid Cloud, Cloud RBAC will only affect those users you wish to administrate your clusters and account in the Cloud UI.
|
||||
|
||||
Additionally, Database API Keys are already available in Hybrid Clusters by accessing the Database UI directly through your ingress.
|
||||
|
||||
## 8. Will this allow me to segregate my dev and admin user access?
|
||||
|
||||
Cloud RBAC currently covers permissions within the cloud console only. The ability to control access to individual clusters and collections is not yet available, but is on our roadmap.
|
||||
|
||||
Today, it is possible to provide dev users with only Database API keys, which will let them authenticate into clusters programmatically. However, for UI access to Managed Cloud Clusters, they will still need access via the Cloud Console.
|
||||
|
||||
In the future, we plan to add the ability to restrict specific cloud identities per resource (cluster or collection) for Managed Cloud as well.
|
||||
|
||||
For Hybrid Clusters, where the Cluster Dashboard UI access is not routed through Qdrant Cloud, it is possible to leverage the built-in API Key RBAC to restrict access when accessing the Cluster UI directly.
|
||||
|
||||
For the administration of clusters and cloud resources with Hybrid you would then only permit trusted admin users into your cloud admin console, and the Cloud RBAC feature will let you control the permissions at this level for those users.
|
||||
|
||||
## 9. Does enabling Cloud RBAC incur any extra cost?
|
||||
|
||||
No, this feature will eventually be enabled for all users in Qdrant Cloud, and we are reaching out to existing customers to gather feedback.
|
||||
|
||||
## 10. I use Cloud Admin Keys, will Cloud RBAC apply to these as well?
|
||||
|
||||
Cloud RBAC was designed to work with both permissions in the UI for Cloud Users to restrict functionality, and also in the backend to work with Admin Keys and programmatic access to the cloud console.
|
||||
|
||||
Configuring permissions for Cloud Management Keys will not available immediately, but is on the roadmap for later.
|
||||
@@ -0,0 +1,103 @@
|
||||
---
|
||||
title: Permission Reference
|
||||
weight: 3
|
||||
---
|
||||
|
||||
# **Permission Reference**
|
||||
|
||||
This document outlines the permissions available in Qdrant Cloud.
|
||||
|
||||
---
|
||||
|
||||
## **Identity and Access Management**
|
||||
Permissions for users, user roles, management keys, and invitations.
|
||||
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:roles` | View roles in the Access Management page. |
|
||||
| `write:roles` | Create and modify roles in the Access Management page. |
|
||||
| `delete:roles` | Remove roles in the Access Management page. |
|
||||
| `read:management_keys` | View Cloud Management Keys in the Access Management page. |
|
||||
| `write:management_keys` | Create and manage Cloud Management Keys. |
|
||||
| `delete:management_keys` | Remove Cloud Management Keys in the Access Management page. |
|
||||
| `write:invites` | Invite new users to an account and revoke invitations. |
|
||||
| `read:invites` | View pending invites in an account. |
|
||||
| `delete:invites` | Remove an invitation. |
|
||||
| `read:users` | View user details in the profile page. <br> - Also applicable in User Management and Role details (User tab). |
|
||||
| `delete:users` | Remove users from an account. <br> - Applicable in User Management and Role details (User tab). |
|
||||
|
||||
---
|
||||
|
||||
## **Cluster**
|
||||
Permissions for API Keys, backups, clusters, and backup schedules.
|
||||
|
||||
### **API Keys**
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:api_keys` | View Database API Keys for managed clusters. |
|
||||
| `write:api_keys` | Create new Database API Keys. |
|
||||
| `delete:api_keys` | Remove Database API Keys. |
|
||||
|
||||
### **Backups**
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:backups` | View backups in the **Backups page** and **Cluster details > Backups tab**. |
|
||||
| `write:backups` | Create backups from the **Backups page** and **Cluster details > Backups tab**. |
|
||||
| `delete:backups` | Remove backups from the **Backups page** and **Cluster details > Backups tab**. |
|
||||
|
||||
### **Clusters**
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:clusters` | View cluster details. |
|
||||
| `write:clusters` | Modify cluster settings in the Cluster details page. |
|
||||
| `delete:clusters` | Delete a cluster from the **Danger Zone** in the Clusters page. |
|
||||
|
||||
### **Backup Schedules**
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:backup_schedules` | View backup schedules in the **Backups page** and **Cluster details > Backups tab**. |
|
||||
| `write:backup_schedules` | Create backup schedules from the **Backups page** and **Cluster details > Backups tab**. |
|
||||
| `delete:backup_schedules` | Remove backup schedules from the **Backups page** and **Cluster details > Backups tab**. |
|
||||
|
||||
---
|
||||
|
||||
## **Hybrid Cloud**
|
||||
Permissions for hybrid cloud environments.
|
||||
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:hybrid_cloud_environments` | View hybrid cloud details. |
|
||||
| `write:hybrid_cloud_environments` | Modify hybrid cloud settings. |
|
||||
| `delete:hybrid_cloud_environments` | Remove a hybrid cloud cluster. |
|
||||
|
||||
---
|
||||
|
||||
## **Payment & Billing**
|
||||
Permissions for payment methods and billing information.
|
||||
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:payment_information` | View payment methods and billing details. |
|
||||
| `write:payment_information` | Modify or remove payment methods and billing details. |
|
||||
|
||||
---
|
||||
|
||||
## **Account Management**
|
||||
Permissions for managing user accounts.
|
||||
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:account` | View account details that the user is a part of. |
|
||||
| `write:account` | Modify account details such as:<br> - Editing the account name<br> - Setting an account as default<br> - Leaving an account<br> **(Only available to Owners)** |
|
||||
| `delete:account` | Remove an account from:<br> - The **Profile page** (list of user accounts).<br> - The **active account** (if the user is an owner/admin). |
|
||||
|
||||
---
|
||||
|
||||
## **Profile**
|
||||
Permissions for accessing personal profile information.
|
||||
|
||||
| Permission | Description |
|
||||
|------------|------------|
|
||||
| `read:profile` | View the user’s own profile information.<br> **(Assigned to all users by default)** |
|
||||
|
||||
---
|
||||
@@ -0,0 +1,61 @@
|
||||
---
|
||||
title: Role Management
|
||||
weight: 1
|
||||
---
|
||||
|
||||
# Role Management
|
||||
|
||||
|
||||
|
||||
> 💡 You can access this in **Access Management > User & Role Management** *if available see [this page for details](/documentation/cloud-rbac/).*
|
||||
|
||||
|
||||
A **Role** contains a set of **permissions** that define the ability to perform or control specific actions in Qdrant Cloud. Permissions are accessible through the Permissions tab in the Role Details page and offer fine-grained access control, logically grouped for easy identification.
|
||||
|
||||
|
||||
## Built-In Roles
|
||||
|
||||
Qdrant Cloud includes some built-in roles for common use-cases. The permissions for these built-in roles cannot be changed.
|
||||
|
||||
There are three types:
|
||||
|
||||
- The **Base Role** is assigned to all users, and provides the minimum privileges required to access Qdrant Cloud.
|
||||
- The **Admin Role** has all available permissions, except for account write permissions.
|
||||
- The **Owner Role** has all available permissions assigned, including account write permissions. There can only be one Owner per account currently.
|
||||
|
||||

|
||||
|
||||
## Custom Roles
|
||||
|
||||
An authorized user can create their own custom roles with specific sets of permissions, giving them more control over who has what access to which resource.
|
||||
|
||||

|
||||
|
||||
### Creating a Custom Role
|
||||
|
||||
To create a new custom role, click on the **Add** button at the top-right corner of the **Custom Roles** list.
|
||||
|
||||
- **Role Name**: Must be unique across roles.
|
||||
- **Role Description**: Brief description of the role’s purpose.
|
||||
|
||||
Once created, the new role will appear under the **Custom Roles** section in the navigation.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
### Editing a Custom Role
|
||||
|
||||
To update a specific role's permissions, select it from the list and click on the **Permissions** tab. Here, you'll find logically grouped options that are easy to identify and edit as needed. Once you've made your changes, save them to apply the updated permissions to the role.
|
||||
|
||||

|
||||
|
||||
### Renaming, Deleting and Duplicating a Custom Role
|
||||
|
||||
Each custom role can be renamed, duplicated or deleted via the action buttons located to the right of the role title bar.
|
||||
|
||||
- **Rename**: Opens a dialog allowing users to update both the role name and description.
|
||||
- **Delete**: Triggers a confirmation prompt to confirm the deletion. Once confirmed, this action is irreversible. Any users assigned to the deleted role will automatically be unassigned from it.
|
||||
- **Duplicate:** Opens a dialog asking for a confirmation and also allowing users to view the list of permissions that will be assigned to the duplicated role
|
||||
|
||||

|
||||
@@ -0,0 +1,53 @@
|
||||
---
|
||||
title: User Management
|
||||
weight: 2
|
||||
---
|
||||
|
||||
|
||||
# User Management
|
||||
|
||||
|
||||
|
||||
> 💡 You can access this in **Access Management > User & Role Management** *if available see [this page for details](/documentation/cloud-rbac/).*
|
||||
|
||||
|
||||
|
||||
|
||||
## Inviting Users to an Account
|
||||
|
||||
|
||||
Users can be invited via the **User Management** section, where they are assigned the **Base role** by default. Additionally, users have the option to select a specific role when inviting another user. The **Base role** is a predefined role with minimal permissions, granting users access to the platform while restricting them to viewing only their own profile.
|
||||
|
||||

|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
### Inviting Users from a Role
|
||||
|
||||
Users can be invited attached to a specific role by inviting them through the **Role Details** page - just click on the Users tab and follow the prompts.
|
||||
|
||||
Once accepted, they'll be assigned that role's permissions, along with the base role.
|
||||
|
||||

|
||||
|
||||
### Revoking an Invitation
|
||||
|
||||
Before being accepted, an Admin/Owner can cancel a pending invite directly on either the **User Management** or **Role Details** page.
|
||||
|
||||

|
||||
|
||||
## Updating a User’s Roles
|
||||
|
||||
Authorized users can give or take away roles from users in **User Management**.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
## Removing a User from an Account
|
||||
|
||||
Users can be removed from an account by clicking on their name in either **User Management** (via Actions). This option is only available after they've accepted the invitation to join, ensuring that only active users can be removed.
|
||||
|
||||

|
||||
BIN
Binary file not shown.
|
After Width: | Height: | Size: 22 KiB |
@@ -1,11 +1,11 @@
|
||||
---
|
||||
title: Qdrant Cloud API
|
||||
weight: 26
|
||||
partition: cloud
|
||||
weight: 27
|
||||
partition: cloud
|
||||
---
|
||||
# Qdrant Cloud API
|
||||
# Qdrant Cloud API
|
||||
|
||||
The Qdrant Cloud API lets you manage Cloud accounts and their respective Qdrant clusters. You can use this API to manage your clusters, authentication methods, and cloud configurations.
|
||||
The Qdrant Cloud API lets you manage Cloud accounts and their respective Qdrant clusters. You can use this API to manage your clusters, authentication methods, and cloud configurations.
|
||||
|
||||
| REST API | Documentation |
|
||||
| -------- | ------------------------------------------------------------------------------------ |
|
||||
@@ -34,14 +34,14 @@ curl -X 'GET' \
|
||||
|
||||
This request will return a list of clusters associated with your account in JSON format.
|
||||
|
||||
## Cluster Management
|
||||
Use these endpoints to create and manage your Qdrant database clusters. The API supports fine-grained control over cluster resources (CPU, RAM, disk), node configurations, tolerations, and other operational characteristics across all cloud providers (AWS, GCP, Azure) and their respective regions in Qdrant Cloud, as well as Hybrid Cloud.
|
||||
## Cluster Management
|
||||
Use these endpoints to create and manage your Qdrant database clusters. The API supports fine-grained control over cluster resources (CPU, RAM, disk), node configurations, tolerations, and other operational characteristics across all cloud providers (AWS, GCP, Azure) and their respective regions in Qdrant Cloud, as well as Hybrid Cloud.
|
||||
- **Get Cluster by ID**: Retrieve detailed information about a specific cluster using the cluster ID and associated account ID.
|
||||
- **Delete Cluster**: Remove a cluster, with optional deletion of backups.
|
||||
- **Update Cluster**: Apply modifications to a cluster's configuration.
|
||||
- **List Clusters**: Get all clusters associated with a specific account, filtered by region or other criteria.
|
||||
- **Create Cluster**: Add new clusters to the account with configurable parameters such as nodes, cloud provider, and regions.
|
||||
- **Get Booking**: Manage hosting across various cloud providers (AWS, GCP, Azure) and their respective regions.
|
||||
- **Get Booking**: Manage hosting across various cloud providers (AWS, GCP, Azure) and their respective regions.
|
||||
|
||||
## Cluster Authentication Management
|
||||
Use these endpoints to manage your cluster API keys.
|
||||
|
||||
Reference in New Issue
Block a user