Grafana Cloud 앱 플러그인 역할 정의

Grafana Cloud 앱 플러그인 역할 정의 (Grafana Cloud app plugin role definitions)

이 페이지는 Grafana Cloud 앱 플러그인에 사용 가능한 RBAC 역할을 나열해요. 플러그인 역할은 특정 플러그인 기능에 대한 접근을 제어하며 사용자·팀·기본 역할에 지정할 수 있어요. 앱 플러그인에서 RBAC가 동작하는 일반적인 방법은 "RBAC for app plugins" 문서를 참고하세요.

출처: 문서

본문

Note: Grafana Cloud에서 사용 가능해요. 서드파티 플러그인은 자체 RBAC 역할을 정의할 수 있어요. 이 페이지는 Grafana Cloud 앱 플러그인의 역할만 다룹니다. 서드파티 플러그인의 사용 가능한 역할은 해당 문서를 참고하세요.

기본 역할별 기본 플러그인 권한

사용자에게 기본 조직 역할(Viewer, Editor, Admin)을 지정하면 자동으로 기본 플러그인 권한을 받아요. 다음 표는 각 Grafana Cloud 플러그인의 기본 접근 레벨을 요약해요:

Plugin Viewer Editor Admin
Adaptive Logs Read exemptions Read exemptions Admin access
Adaptive Metrics Read recommendations, exemptions Read recommendations, exemptions Admin access
Adaptive Traces Read recommendations Read recommendations Admin access
Application Observability View access View access Admin access
Assistant Chat access, user rules/quickstarts + MCP servers, investigations + Tenant-wide settings
Cloud Provider Read access Read access Provider-specific write access
Cost Attributions Read attributions Read attributions Read attributions
Cost Management and Billing Full access
Database Observability Read access Read access Admin access
Fleet Management (Collector) Read access Read access Full access
Frontend Observability Read apps, source maps + Write apps, source maps + Delete apps
Grafana Auth Write access policies
IRM Read all + Write alert groups, schedules, maintenance, user settings + Write integrations, escalation chains, etc.
k6 Read settings + Write settings Admin access
Knowledge Graph Read assertions + Write configuration and rules + Full write access
Kubernetes Monitoring Read all Read all Admin access
Labels Read labels + Create, edit, delete labels + Full write access
Machine Learning Read forecasting, outliers, sift + Write forecasting, outliers, sift + Full write access
OnCall Read all + Write alert groups, schedules, maintenance, user settings + Write integrations, escalation chains, etc.
Private Data Connect Full access
Session Replay View session recordings View session recordings View session recordings
SLO Read SLOs Create, edit, delete SLOs + Modify org preferences
Synthetic Monitoring Read checks, probes, alerts, thresholds + Create, edit, delete checks, probes, alerts, thresholds + Manage access tokens

Note: 위 권한은 사용자의 조직 역할에 따라 자동 부여돼요. 아래에 나열된 추가 플러그인-특정 역할을 지정해 더 세분화된 접근을 부여할 수 있어요.

플러그인별 역할 (요약)

각 플러그인은 고유한 역할을 정의하며, 역할 이름 형식은 plugins:<plugin-id>:<role>이에요. 주요 플러그인별 역할:

  • Adaptive Logs (grafana-adaptivelogs-app): admin, patterns-editor, patterns-reader, segments-admin, expiring-exemptions-user, plugin-access
  • Adaptive Metrics (grafana-adaptive-metrics-app): admin, rules-editor, rules-reader, exemptions-editor, exemptions-reader, segments-editor, segments-reader, config-editor, config-reader, plugin-access
  • Adaptive Traces (grafana-adaptivetraces-app): admin
  • Application Observability (grafana-app-observability-app): admin, viewer
  • Cloud Provider (grafana-csp-app): aws-writer, azure-writer, gcp-writer, reader
  • Cost Attributions (grafana-attributions-app): cost-attributions-viewer
  • Cost Management and Billing (grafana-cmab-app): full-admin, billing-and-usage-reader, invoice-reader, cost-attribution-admin, cost-attribution-reader, usage-alerts-admin, usage-alerts-reader
  • Database Observability (grafana-dbo11y-app): admin, reader
  • Easystart / Integrations (grafana-easystart-app): integrations-writer
  • Fleet Management (grafana-collector-app): collector-app-admin, collector-app-reader
  • Frontend Observability (grafana-kowalski-app): frontend-observability-admin, frontend-observability-editor, frontend-observability-viewer, frontend-observability-sourcemap-uploader
  • Grafana Assistant (grafana-assistant-app): assistant-admin, assistant-mcp-user, assistant-user, assistant-investigation-user
  • Grafana Auth (grafana-auth-app): writer
  • IRM (grafana-irm-app): Core (admin, editor, reader, oncaller, notifications-receiver, incident-access), Alert groups (alert-groups-reader, alert-groups-editor, alert-groups-direct-paging), Integrations (integrations-reader, integrations-editor), Escalation chains (escalation-chains-reader, escalation-chains-editor), Schedules (schedules-reader, schedules-editor), ChatOps (chatops-reader, chatops-editor), Outgoing webhooks (outgoing-webhooks-reader, outgoing-webhooks-editor), Maintenance (maintenance-reader, maintenance-editor), API keys (api-keys-reader, api-keys-editor), User settings (user-settings-reader, user-settings-editor, user-settings-admin), Notification/general settings (notification-settings-reader, notification-settings-editor, settings-reader, settings-editor)
  • k6 Cloud (k6-app): admin, editor, reader
  • Knowledge Graph (grafana-asserts-app): knowledge-graph-writer, knowledge-graph-reader, knowledge-graph-access
  • Kubernetes Monitoring (grafana-k8s-app): admin, reader
  • Labels (grafana-labels-app): labels-writer, labels-reader
  • Machine Learning (grafana-ml-app): ml-editor, ml-viewer, sift-editor, sift-viewer
  • Private Data Connect (grafana-pdc-app): private-networks-read, private-networks-write
  • Session Replay (grafana-sessionreplay-app): recordings-viewer
  • SLO (grafana-slo-app): slo-reader, slo-writer, slo-admin
  • Synthetic Monitoring (grafana-synthetic-monitoring-app): Core (admin, editor, reader), Granular (checks-reader, checks-writer, probes-reader, probes-writer, alerts-reader, alerts-writer, thresholds-reader, thresholds-writer, access-tokens-writer)

플러그인 역할 이름과 각 역할의 정확한 설명은 Grafana 원문 페이지의 플러그인별 섹션을 참고하세요.

역할 지정 (Role assignment)

플러그인 역할은 다음에 지정할 수 있어요:

  • Users: 개별 사용자 계정
  • Teams: 팀의 모든 멤버가 역할 상속
  • Basic Roles: Viewer, Editor, Admin 기본 역할에 추가

역할 지정 방법:

  • UI: Administration > Users/Teams > 사용자/팀 선택 > Roles 탭
  • API: PUT /api/access-control/users/{userId}/roles 또는 PUT /api/access-control/teams/{teamId}/roles

RBAC 역할 관리에 대한 자세한 내용은 "Manage RBAC roles" 문서를 참고하세요.

플러그인 역할 조회

API로 Grafana Cloud 스택의 사용 가능한 플러그인 역할을 조회할 수 있어요:

curl -s -H "Authorization: Bearer YOUR_S...OKEN" \
  "https://YOUR_STACK.grafana.net/api/access-control/roles?includeHidden=true" | \
  jq '[.[] | select(.name | startswith("plugins:"))]'

관련 문서

더 알아보기 (Learn more)