Before you start
The next chapters explain how to configure and bootstrap realm-based access control and how to set up your first realm administration environment. This chapter provides some considerations to make before you start.
Considerations about your realm administration concept
To ease the configuration of your realm administration, design your realm environment concept beforehand. Consider the following:
- Who is going to manage all realms (create realms, create realm roles, create and edit delegations)? Note that this user must be assigned two kind of roles:
- The global role to perform Realm Management. This role is not defined in the Adminapp, but set in the IAM configuration. Think of a suitable name. In these instructions, we use the name “realms-manager”.
- A realm role that holds all available permissions. In these instructions, we call this role “admin”. It is created in the Realm Management functionality in the Adminapp.
- Notice
For a realm admin to be able to manage all realms, be sure to connect this “admin” role via delegations to each existing realm, with all permissions included. This is because an admin can assign only those permissions to a role in a realm that they already have themselves through another delegation for this realm.
- Which realms (= user partitions) should exist? For example, realm-north, realm-south, to separately manage users in the locations North and South.
- Which roles should be available per realm and how to call them? For example, helpdesk-admin, user-admin, user-monitor.
- Which actions should these roles be able to perform? Note that the permissions assigned to a specific role may differ per realm.
- How to bind the above together in delegations?