Each user has his/her own dedicated project. Projects are used to divide resources and workloads for different users.
To further strengthen security, IEC provides Policy Engine (gatekeeper). Users can configure a white-list through this tool to only allow specific applications to use sensitive resources such as host-path.
- Project Isolation: Assign independent resources and workload space to each user.
- Whitelist Settings: Configure application access permissions using policy engine.
For more information, see Creating a Project and Adding a Project Member.
In addition, EonKube allows fine-grained permission configuration to ensure that user and user groups can have the right permission to the system. This ensures system security.
EonKube provides three preset permission types: system administrator, standard user and basic user.
- Administrator: These users have full control over the entire system. They can perform all ad-ministrative operations, including managing clusters, users, resources, and settings.
- Standard User: These users can use the cluster. They can deploy and manage applications, but cannot change global settings or manage other users.
- User-Base: User-Base users have login-access only.
For more information about editing cluster membership, see Editing Cluster Membership.