Bug 1419384 - [DOC] Wrong system role usage in direct docker push section
Summary: [DOC] Wrong system role usage in direct docker push section
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Documentation
Version: 3.4.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: ---
Assignee: Gaurav Nelson
QA Contact: Vikram Goyal
Vikram Goyal
Depends On:
TreeView+ depends on / blocked
Reported: 2017-02-06 02:08 UTC by Takayoshi Kimura
Modified: 2020-03-11 15:44 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-05-23 02:25:07 UTC
Target Upstream Version:

Attachments (Terms of Use)

Description Takayoshi Kimura 2017-02-06 02:08:52 UTC
Document URL: https://docs.openshift.com/container-platform/3.4/install_config/registry/accessing_registry.html#access

Section Number and Name:  Installation and Configuration - Accessing the Registry - Accessing the Registry Directly

Describe the issue: 

It gives special roles to normal users like "system:registry" and "system:image-builder". They are roles for system users (in other words service accounts), the "system:registry" for service account default/registry and "system:image-builder" for service account */builder.

These "system:" roles are not supposed to bind to normal users.

Also it gives "admin" role to a user on openshift project, which is too wide and not recommended.

Suggestions for improvement: 

To allow a user to docker push to particular project, we need:

oadm policy add-role-to-user registry-editor USERNAME -n PROJECT

For example, user joe and project openshift:

oadm policy add-role-to-user registry-editor joe -n openshift

For pull only acceess we can use "registry-viewer" role, also worth to put here.

Additional information:

Comment 2 Gaurav Nelson 2018-04-26 13:49:37 UTC
Updated the docs with suggestions in https://github.com/openshift/openshift-docs/pull/8919

Comment 3 Gaurav Nelson 2018-05-02 01:14:49 UTC
@tkimura Can you please review the changes in https://github.com/openshift/openshift-docs/pull/8919

Comment 4 Takayoshi Kimura 2018-05-14 23:51:04 UTC
Added review comment.

Comment 5 openshift-github-bot 2018-05-18 05:07:23 UTC
Commit pushed to master at https://github.com/openshift/openshift-docs

Merge pull request #8919 from gaurav-nelson/bug1419384-fixes

added registry-editor and registry-viewer roles info

Note You need to log in before you can comment on or make changes to this bug.