Setting Up Policy-Based Security
In HPE Ezmeral Runtime Enterprise, policy-based security (PBS) for HPE Ezmeral Data
Fabric on Kubernetes is enabled by default. Before you can begin creating security policies,
you must use maprcli
commands to perform some set up tasks.
In HPE Ezmeral Runtime Enterprise, policy-based security (PBS) for HPE Ezmeral Data Fabric on
Kubernetes is enabled by default. Before you can begin creating security policies, you must
use maprcli
commands to do the following:
-
Designate a global policy master.
You must set one cluster as the global policy master before you can create security policies. The cluster set as the global policy master is the only cluster on which you can create or update security policies.
-
Set permissions for creating and managing security policies.
To create security policies, an administrator must have cluster-level
cp
(create security policy) permission. By default, thecp
permission is not assigned to all administrators. Administrators with cluster-levela (admin)
permission can grantcp
permission to themselves or other administrators.
For more information about these tasks, see Policy-Based Security and Policy-Based Security Quick Reference in the HPE Ezmeral Data Fabric documentation.