cp-demo icon indicating copy to clipboard operation
cp-demo copied to clipboard

Too many users in KafkaDevelopers LDAP Group

Open chuck-confluent opened this issue 3 years ago • 0 comments

Here is where users are added to groups: https://github.com/confluentinc/cp-demo/blob/6.2.1-post/scripts/security/ldap_users/20_group_add.ldif

We need to use groups to showcase the power of RBAC. I would suggest two different groups, KafkaDevelopersA and KafkaDevelopersB, with alice and barnie in A and alice and charlie in B. This would make it possible to illustrate the benefits of RBAC a bit better. For example, alice would receive permissions associated with both groups.

I don't see any reason to add the rest of the users to the kafka developers group. Those are all confluent system users who don't need to be in group of developers.

chuck-confluent avatar Oct 08 '21 22:10 chuck-confluent