Previous Topic

Next Topic

Book Contents

Book Index

Role Based Authorization scenario

The Big Data team uses Control-M for Hadoop and Application Integrator, spread across several Control-M/Agents. The team has been granted the Full access level to Control-M/Agents with the tag big_data. On these Control-M/Agents, the team is granted the permission to view and manage specific Application Plug-ins and do not have access to any other. In addition, the team is granted access to Hadoop and Application Integrator connection profiles, but only if the connection profile name starts with BIGDATA. The team does not have access to AWS and Azure.

The Cloud team uses Control-M for AWS and Control-M for Azure spread across several Control-M/Agents. The team has been granted the Full access level to Control-M/Agents with the tags AWS and Azure. On these Control-M/Agents, the team is granted the permission to view and manage specific Application Plug-ins and do not have access to any other. In addition, the team is granted access to AWS and Azure connection profiles, but only if the connection profile name starts with AWS or Azure. The team does not have access to BIGDATA.

The following tables illustrate the authorization differences between the two teams:

Agents

Control-M

Agent Tag

Access Level

*

big_data

Full

*

Cloud

Full

Application Plug-ins

Control-M

Agent Tag

Plug-in Type

Access Level

*

big_data

Hadoop

Full

*

big_data

myAIJob1

Full

*

Cloud

AWS

Full

*

Cloud

Azure

Full

Local Connection Profiles

Local connection profiles can use the tags that appear in the following example because they can be mapped to specific local connection profiles that reside on the Control-M/Agents.

Name

Control-M

Agent Tag

Plug-in Type

Access Level

BIGDATA*

Server1

big_data

Hadoop

Full

BIGDATA*

Server1

big_data

myAIJob1

Full

*

Server1

big_data

Hadoop

Browse

AWS*

Server1

Cloud

AWS

Full

Azure*

Server1

Cloud

Azure

Full

*

Server1

Cloud

AWS, Azure

Browse

Centralized Connection Profiles

Centralized connection profiles are deployed to all Control-M/Agents. Therefore, you need to verify that the Control-M and Agent Tag fields are set to *.

Name

Control-M

Agent Tag

Plug-in Type

Access Level

BIGDATA*

*

*

Hadoop

Full

BIGDATA*

*

*

myAIJob1

Full

*

*

*

Hadoop

Browse

AWS*

*

*

AWS

Full

Azure*

*

*

Azure

Full

*

*

*

AWS, Azure

Browse

Parent Topic

Role Based Administration authorizations