Controlling just in time access to a cluster
Examples include a system and computer-implemented method to receive a notification from an application programming interface (API) of creation of a just in time (JIT) grant, the JIT grant defining a request for a user to be authorized to access a cluster according to a JIT policy; determine if access to the cluster by the user is authorized according to the JIT policy; grant access to the user to the cluster when access is authorized according to the JIT policy; and send a notification to the API that access by the user to the cluster is granted.
1 . A role-based access control system, comprising:
a processing device; and
a memory device,
the processing device configurable to cause:
processing an access control policy of just in time (JIT) access received via an interface, the access control policy specifying a role and an expiration time;
determining that access to a resource by a user is authorized according to the access control policy based, at least in part, on a role of the user;
granting, to the user, JIT access to the resource until expiration of the expiration time responsive to determining that access is authorized according to the access control policy, wherein granting, to the user, JIT access to the resource includes creating a role binding for the user; and
revoking access by the user to the resource in response to expiration of the expiration time, wherein revoking access includes deleting the role binding for the user.
2 . The role-based access control system of claim 1 , wherein the role binding grants permissions defined in a role to users within an identity provider group.
3 . The role-based access control system of claim 2 , wherein deleting the role binding comprises deleting an account associated with the role.
4 . The role-based access control system of claim 1 , the processing device further configurable to cause:
sending a security assertion markup language assertion to a service provider associated with the resource prior to access to the resource being granted.
5 . The role-based access control system of claim 1 , the processing device further configurable to cause:
associating a group with the access control policy; and
assigning the role to the group.
6 . The role-based access control system of claim 1 , the processing device further configurable to cause:
displaying, on a device of an authorized administrator, a user interface configurable to allow the authorized administrator to specify the expiration time.
7 . The role-based access control system of claim 1 , the processing device further configurable to cause:
associating a resource type with the access control policy, the resource type being an application.
8 . A computer-implemented method, comprising:
processing an access control policy of just in time (JIT) access received via an interface, the access control policy specifying a role and an expiration time;
determining that access to a resource by a user is authorized according to the access control policy based, at least in part, on a role of the user;
granting, to the user, JIT access to the resource until expiration of the expiration time responsive to determining that access is authorized according to the access control policy, wherein granting, to the user, JIT access to the resource includes creating a role binding for the user; and
revoking access by the user to the resource in response to expiration of the expiration time, wherein revoking access includes deleting the role binding for the user.
9 . The computer-implemented method of claim 8 , wherein the role binding grants permissions defined in a role to users within an identity provider group.
10 . The computer-implemented method of claim 9 , wherein deleting the role binding includes deleting an account associated with the role.
11 . The computer-implemented method of claim 8 , the method further comprising:
sending a security assertion markup language assertion to a service provider associated with the resource prior to access to the resource being granted.
12 . The computer-implemented method of claim 8 , the method further comprising:
associating a group with the access control policy; and
assigning the role to the group.
13 . The computer-implemented method of claim 8 , the method further comprising:
displaying, on a device of an authorized administrator, a user interface configurable to allow the authorized administrator to specify the expiration time.
14 . The computer-implemented method of claim 8 , the method further comprising:
associating a resource type with the access control policy, the resource type being an application.
15 . At least one tangible non-transitory machine-readable medium comprising a plurality of instructions that in response to being executed by a processor in a computing system, are configurable to cause:
processing an access control policy of just in time (JIT) access received via an interface, the access control policy specifying a role and an expiration time;
determining that access to a resource by a user is authorized according to the access control policy based, at least in part, on a role of the user;
granting, to the user, JIT access to the resource until expiration of the expiration time responsive to determining that access is authorized according to the access control policy, wherein granting, to the user, JIT access to the resource includes creating a role binding for the user; and
revoking access by the user to the resource in response to expiration of the expiration time, wherein revoking access includes deleting the role binding for the user.
16 . The at least one tangible non-transitory machine-readable medium of claim 15 , wherein the role binding grants permissions defined in a role to users within an identity provider group.
17 . The at least one tangible non-transitory machine-readable medium of claim 16 , wherein deleting the role binding includes deleting an account associated with the role.
18 . The at least one tangible non-transitory machine-readable medium of claim 15 , the plurality of instructions being further configured to cause:
sending a security assertion markup language assertion to a service provider associated with the resource prior to access to the resource being granted.
19 . The at least one tangible non-transitory machine-readable medium of claim 15 , the plurality of instructions being further configured to cause:
associating a group with the access control policy; and
assigning the role to the group.
20 . The at least one tangible non-transitory machine-readable medium of claim 15 , the plurality of instructions being further configured to cause:
displaying, on a device of an authorized administrator, a user interface configurable to allow the authorized administrator to specify the expiration time.