모니터를 위한 RBAC 설정하기
모니터를 위한 RBAC 설정하기 (How to set up RBAC for Monitors)
모니터는 시스템의 잠재적 문제를 팀에 알려줘요. 승인된 사용자만 모니터를 편집할 수 있게 하면 모니터 구성에서 발생하는 우발적인 변경을 막을 수 있어요.
각 개별 모니터의 편집 권한을 특정 역할(role)로 제한하면 모니터를 안전하게 관리할 수 있어요.
출처: 문서
본문
역할 설정하기 (Set up roles)
기본 및 커스텀 역할, 커스텀 역할 생성 방법, 역할에 권한 부여 방법, 사용자에게 역할 할당 방법에 대한 자세한 내용은 역할 기반 접근 제어(Role Based Access Control) 문서를 참고해요.
모니터에 대한 접근 제한하기 (Restrict access to monitors)
{% tab title="UI" %}
- 새 모니터를 만들거나 기존 모니터를 편집해 모니터 편집 페이지로 이동해요.
- 양식 맨 아래에서 생성자(creator) 외에 모니터를 편집할 수 있는 역할을 지정해요.
{% image source="https://docs.dd-static.net/images/monitors/guide/monitor_rbac_restricted.56ceba552f21694f6241dfcb82677f13.jpg?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/monitor_rbac_restricted.56ceba552f21694f6241dfcb82677f13.jpg?auto=format&fit=max&w=850&dpr=2 2x" alt="RBAC Restricted Monitor" /%}
자세한 내용은 모니터 권한(Monitors Permissions) 문서를 참고해요. {% /tab %}
{% tab title="API" %} List Roles API 엔드포인트로 역할 목록과 역할 ID를 가져와요.
curl --request GET 'https://api.datadoghq.com/api/v2/roles' \
--header 'DD-API-KEY: *** \
--header 'DD-APPLICATION-KEY: <DD-APPLICATION-KEY>'
{
"meta": {
"page": {
"total_filtered_count": 4,
"total_count": 4
}
},
"data": [
{
"type": "roles",
"id": "89f5dh86-e470-11f8-e26f-4h656a27d9cc",
"attributes": {
"name": "Corp IT Eng - User Onboarding",
"created_at": "2018-11-05T21:19:54.105604+00:00",
"modified_at": "2018-11-05T21:19:54.105604+00:00",
"user_count": 4
},
"relationships": {
"permissions": {
"data": [
{
"type": "permissions",
"id": "984d2rt4-d5b4-13e8-a5yf-a7f560d33029"
},
...
]
}
}
},
...
]
}
Create 또는 Edit a monitor API 엔드포인트와 restricted_roles 파라미터를 사용해 모니터 편집을 특정 역할 집합과 모니터 생성자로 제한해요.
참고: 하나 또는 여러 개의 역할 UUID를 지정할 수 있어요. restricted_roles를 null로 설정하면 모니터 쓰기 권한(Monitor Write permissions)이 있는 모든 사용자가 모니터를 편집할 수 있어요.
curl --location --request POST 'https://api.datadoghq.com/api/v1/monitor' \
--header 'Content-Type: application/json' \
--header 'DD-API-KEY: *** \
--header 'DD-APPLICATION-KEY: <DD-APPLICATION-KEY>' \
--data-raw '{
"message": "You may need to add web hosts if this is consistently high.",
"name": "Bytes received on host0",
"options": {
"no_data_timeframe": 20,
"notify_no_data": true
},
"query": "avg(last_5m):sum:system.net.bytes_rcvd{host:host0} \u003e 100",
"tags": [
"app:webserver",
"frontend"
],
"type": "query alert",
"restricted_roles": ["89f5dh86-e470-11f8-e26f-4h656a27d9cc"]
}'
자세한 내용은 Roles 및 Monitors API Reference 문서를 참고해요. {% /tab %}
제한 역할 (Restricted roles)
Datadog는 역할 제한(role restriction) 옵션을 통해 모니터 편집을 특정 역할로 제한할 수 있게 해줘요. 이를 통해 어떤 사용자가 모니터를 편집할 수 있는지 유연하게 정의할 수 있어요.
API (API)
API 또는 Terraform으로 관리되는 모니터의 정의는 restricted_roles 파라미터로 업데이트할 수 있어요. 또한 Restriction Policies 엔드포인트를 사용해 모니터에 대한 접근 제어 규칙을 정의할 수 있는데, 관계 집합(예: editor와 viewer)을 허용된 주체(principal) 집합(예: 역할, 팀, 사용자)에 매핑해요. 제한 정책(restriction policy)은 모니터에서 누가 어떤 작업을 수행할 수 있는지 결정해요.
자세한 내용은 Edit a monitor API 엔드포인트와 Restriction Policies API 문서를 참고해요.
UI (UI)
UI에서 생성된 모든 새 모니터는 restricted_roles 파라미터를 사용해요. 또한 모든 모니터는 기본 메커니즘과 관계없이 역할 제한 옵션을 표시해요:
{% image source="https://docs.dd-static.net/images/monitors/guide/monitor_rbac_non_restricted.72dbbf62481a657393f242c0a9653250.jpg?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/monitor_rbac_non_restricted.72dbbf62481a657393f242c0a9653250.jpg?auto=format&fit=max&w=850&dpr=2 2x" alt="RBAC Non Restricted Monitor" /%}