Admin SDK로 역할과 권한 관리하기
Admin SDK로 역할과 권한 관리하기
코드로 역할 기반 접근 제어(RBAC)를 정의할 수 있어요.
출처: 문서
본문
개요 (Overview)
Confident AI는 역할 기반 접근 제어(RBAC)를 사용해요. 접근은 세 가지 구성 요소를 조합해 부여돼요 — 권한을 정책으로 묶고, 정책을 역할로 묶고, 역할을 멤버에게 할당해요:
- 권한(Permissions) 은 부여할 수 있는 원자적(atomic) 행동이에요 (예:
traces:read). 플랫폼이 미리 정의하므로 나열만 할 수 있어요. - 정책(Policies) 은 권한을 묶어 이름 붙인 것이에요.
- 역할(Roles) 은 멤버에게 할당하는 정책 묶음에 이름을 붙인 것이에요.
%%{init: {'flowchart': {'nodeSpacing': 55, 'rankSpacing': 90}}}%%
flowchart LR
Perm["Permissions<br/>(atomic actions)"] -->|bundled into| Pol["Policies"]
Pol -->|bundled into| Role["Roles"]
Role -->|assigned to| Member["Members"]
각 구성 요소는 조직과 프로젝트 수준 모두에 독립적으로 존재해요. 조직 수준 역할은 조직 전체의 접근을 다스리고, 프로젝트 수준 역할은 단일 프로젝트 안의 접근을 다스려요. RBAC 개념을 더 배우려면 RBAC를 참고해요.
이 페이지의 모든 메서드는 조직 API 키가 필요해요. 클라이언트 생성은 퀵스타트를 참고해요. 권한, 정책, 역할은 두 클라이언트 모두의
iam네임스페이스 아래에 있어요 —client.organization().iam과client.project(id).iam.
권한 (Permissions)
권한은 읽기 전용이에요. 정책에 붙일 id를 발견하려면 목록을 조회해요.
Python
from confidentai import ConfidentAI
client = ConfidentAI()
org = client.organization()
project = client.project("clq9z3x1k0001la08f7t3g5p2")
permissions = org.iam.permissions.list()
project_permissions = project.iam.permissions.list()
TypeScript
import { ConfidentAI } from "confidentai";
const client = new ConfidentAI();
const org = client.organization();
const project = client.project("clq9z3x1k0001la08f7t3g5p2");
const permissions = await org.iam.permissions.list();
const projectPermissions = await project.iam.permissions.list();
정책 (Policies)
정책은 권한을 함께 묶어요. 위의 권한 목록에서 permission_ids를 제공해요.
정책 목록, 생성, 수정, 삭제 (List, Create, Update & Delete Policies)
각 정책은 name, permission_ids 목록, 그리고 선택적인 description을 가져요.
Python
org = client.organization()
project = client.project("clq9z3x1k0001la08f7t3g5p2")
# List
policies = org.iam.policies.list()
project_policies = project.iam.policies.list()
# Create
policy = org.iam.policies.create(
"Dataset Editor",
permission_ids=["5e9a1c3d-7b2f-4e8a-9c1d-3a6b5f0e2d4c", "8d2c4f6a-1e3b-4c7d-9a5e-2b8f1d0c6a3e"],
description="Can edit datasets",
)
# Update
policy = org.iam.policies.update(
"a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d",
name="Dataset Editor",
permission_ids=["5e9a1c3d-7b2f-4e8a-9c1d-3a6b5f0e2d4c", "8d2c4f6a-1e3b-4c7d-9a5e-2b8f1d0c6a3e", "2a7e9c1d-4b6f-4a8c-1d3e-7f5a9b2c0e4d"],
)
# Delete
org.iam.policies.delete("a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d")
TypeScript
const org = client.organization();
const project = client.project("clq9z3x1k0001la08f7t3g5p2");
// List
const policies = await org.iam.policies.list();
const projectPolicies = await project.iam.policies.list();
// Create
const policy = await org.iam.policies.create({
name: "Dataset Editor",
permissionIds: ["5e9a1c3d-7b2f-4e8a-9c1d-3a6b5f0e2d4c", "8d2c4f6a-1e3b-4c7d-9a5e-2b8f1d0c6a3e"],
description: "Can edit datasets",
});
// Update
const updated = await org.iam.policies.update("a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d", {
name: "Dataset Editor",
permissionIds: ["5e9a1c3d-7b2f-4e8a-9c1d-3a6b5f0e2d4c", "8d2c4f6a-1e3b-4c7d-9a5e-2b8f1d0c6a3e", "2a7e9c1d-4b6f-4a8c-1d3e-7f5a9b2c0e4d"],
});
// Delete
await org.iam.policies.delete("a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d");
프로젝트 스코프 정책도 조직 스코프 정책과 동일한 목록, 생성, 수정, 삭제 연산을 사용해요.
역할 (Roles)
역할은 정책을 함께 묶고 멤버에게 할당돼요. 위의 정책에서 policy_ids를 제공해요.
역할 목록, 생성, 수정, 삭제 (List, Create, Update & Delete Roles)
각 역할은 name, policy_ids 목록, 그리고 선택적인 description을 가져요.
Python
org = client.organization()
project = client.project("clq9z3x1k0001la08f7t3g5p2")
# List
roles = org.iam.roles.list()
project_roles = project.iam.roles.list()
# Create
role = org.iam.roles.create(
"Data Scientist",
policy_ids=["a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d"],
description="Read/write datasets and prompts",
)
# Update
role = org.iam.roles.update(
"b3f1c2a9-7d4e-4c1b-9a2f-1e6d8c0a4b7e",
name="Data Scientist",
policy_ids=["a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d", "c4f8a2e6-1d3b-4e9a-8c7d-5b2f1a0e6d3c"],
)
# Delete
org.iam.roles.delete("b3f1c2a9-7d4e-4c1b-9a2f-1e6d8c0a4b7e")
TypeScript
const org = client.organization();
const project = client.project("clq9z3x1k0001la08f7t3g5p2");
// List
const roles = await org.iam.roles.list();
const projectRoles = await project.iam.roles.list();
// Create
const role = await org.iam.roles.create({
name: "Data Scientist",
policyIds: ["a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d"],
description: "Read/write datasets and prompts",
});
// Update
const updated = await org.iam.roles.update("b3f1c2a9-7d4e-4c1b-9a2f-1e6d8c0a4b7e", {
name: "Data Scientist",
policyIds: ["a17c4e2d-9b3f-4a6c-8d1e-2f5a9c3b7e0d", "c4f8a2e6-1d3b-4e9a-8c7d-5b2f1a0e6d3c"],
});
// Delete
await org.iam.roles.delete("b3f1c2a9-7d4e-4c1b-9a2f-1e6d8c0a4b7e");
프로젝트 스코프 역할도 조직 스코프 역할과 동일한 목록, 생성, 수정, 삭제 연산을 사용해요.
다음 단계 (Next Steps)
역할을 정의했으니, 팀에 할당해요:
멤버와 초대 (Members & Invitations)
멤버와 초대받은 사람에게 역할을 할당해요.
RBAC
RBAC 모델을 깊이 이해해요.