Matching of rights in the web interface and OpenAPI

Rights and permissions for user roles can be set in the solution's web interface or using the Kaspersky Container Security OpenAPI. The table below matches user rights and permissions in the web interface and the elements of requests to the API server.

User rights and permissions in the web interface and OpenAPI

Permission in the web interface

Indication of permitted actions in the web interface

Permission in OpenAPI

Indication of permitted actions in OpenAPI

Inventory

Clusters

View and manage

inventory.assets.clusters

rwxd

Node scan results

View

View and run rescan

inventory.assets.nodes

r

rx

RBAC

View

inventory.rbac

r

Secrets

View

inventory.assets.clusters.secrets

r

Image management

View

View and manage

inventory.assets.registries

r

rwd

Image scan results

View

View and run rescan

inventory.assets.registries.scans

r

rx

CI/CD Scans

View

View and manage

inventory.cicd

r

rwxd

Benchmarks

View

View and run rescan

benchmarks.cis

r

rx

Components

Agents

View and manage

components.agents

rwxd

Core

View

components.core

r

Policies

Scanner policies

View

View and manage

policies.scanner

r

rwxd

Assurance policies

View

View and manage

policies.assurance

r

rwxd

Runtime policies

View

View and manage

policies.runtime

r

rwxd

File Threat Protection settings

View and manage

settings.file-threat-protection

rwxd

User-defined reputation list

View

View and manage

policies.runtime.custom-reputation-list

r

rwxd

Response policies

View

View and manage

policies.response

r

rwxd

Risk acceptance

View

View and manage

policies.risk

r

rwxd

Integration

Registries integrations

View

View and manage

administration.integrations.image.registries

r

rwxd

Signature validators integrations

View

View and manage

administration.integrations.sign-validators

r

rwxd

Notifications integrations

View

View and manage

administration.integrations.notifications

r

rwxd

LDAP integrations

View and manage

administration.integrations.ldap

rwxd

SIEM Integrations

View

View and manage

administration.integrations.siem

r

rwxd

Access management

Users

View

View and manage

administration.users

r

rwxd

Roles

View

View and manage

administration.roles

r

rwxd

Scopes

View

View and manage

administration.scopes

r

rwxd

Default scope

View

View and manage

administration.scopes-global

r

rwxd

Administration

Licensing

View

View and manage

settings.license

r

rwxd

Events

View

administration.events

r

Reports

View

View and manage

administration.reports

r

rwxd

Page top