Granting Access to the Mesos UI

ENTERPRISE

You can grant users access to the Mesos UI. By default, new users have no permissions.

Grant Access by using the GUI

Prerequisite:

  • A DC/OS user account without the dcos:superuser permission.
  1. Log into the DC/OS GUI as a user with the dcos:superuser permission.

    Login

  2. Select Organization and choose Users or Groups.

  3. Select the name of the user or group to grant the permission to.

    Add permission cory

  4. From the Permissions tab, click ADD PERMISSION.

  5. Click INSERT PERMISSION STRING to toggle the dialog.

    Add permission

  6. Copy and paste the permission in the Permissions Strings field. Choose the permission strings based on your security mode and click ADD PERMISSIONS and then Close.

    Disabled

    Mesos master UI and API

    dcos:adminrouter:ops:mesos full
    

    Mesos agent API for accessing task sandboxes and logs, and task exec

    dcos:adminrouter:ops:slave full
    

    Permissive

    Mesos master UI and API

    dcos:adminrouter:ops:mesos full
    

    Mesos agent API for accessing task sandboxes and logs, and task exec

    dcos:adminrouter:ops:slave full
    

    Strict

    Mesos master UI and API

    dcos:adminrouter:ops:mesos full
    

    Mesos agent API for accessing task sandboxes and logs, and task exec

    dcos:adminrouter:ops:slave full
    

You can now send the URL of the Mesos UI for DC/OS to the user: http://<master-public-ip>/mesos/.

Granting Access by using the API

Prerequisites:

Tips:

  • Service resources often include / characters that must be replaced with %252F in curl requests, as shown in the examples below.
  • When using the API to manage permissions, you must create the permission before granting it. If the permission already exists, the API will return an informative message and you can continue to assign the permission.

Disabled

Mesos master UI and API

  1. Create the permission.

    curl -X PUT -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    -H 'Content-Type: application/json' \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:mesos \
    -d '{"description":"Grants access to the Mesos master API/UI and task details"}'
    
  2. Grant the permission to a user (<user-name>).

    curl -X PUT -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:mesos/users/<user-name>/full
    

    Tip: To grant this permission to a group instead of a user, replace /users/<user-name> with /groups/<group-name>.

  3. You can send the URL of the Mesos UI for DC/OS to the user: http://<master-public-ip>/mesos/.

Mesos agent API for accessing task sandboxes and logs, and task exec

  1. Create the permission.

    curl -X PUT \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    -H 'Content-Type: application/json' \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:slave \
    -d '{"description":"Grants access to the Mesos agent API/UI and task details such as logs"}'
    
  2. Grant the permission to a user (<user-name>).

    curl -X PUT -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:slave/users/<user-name>/full
    

    Tip: To grant this permission to a group instead of a user, replace /users/<user-name> with /groups/<group-name>.

Permissive

Mesos master UI and API

  1. Create the permission.

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    -H 'Content-Type: application/json' \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:mesos \
    -d '{"description":"Grants access to the Mesos master API/UI and task details"}'
    
  2. Grant the permission to a user (<user-name>).

    curl -X PUT --cacert dcos-ca.crt -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:mesos/users/<user-name>/full
    

    Tip: To grant this permission to a group instead of a user, replace /users/<user-name> with /groups/<group-name>.

  3. You can send the URL of the Mesos UI for DC/OS to the user: http://<master-public-ip>/mesos/.

Mesos agent API for accessing task sandboxes and logs, and task exec

  1. Create the permission.

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    -H 'Content-Type: application/json' \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:slave \
    -d '{"description":"Grants access to the Mesos agent API/UI and task details such as logs"}'
    
  2. Grant the permission to a user (<user-name>).

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:slave/users/<user-name>/full
    

    Tip: To grant this permission to a group instead of a user, replace /users/<user-name> with /groups/<group-name>.

Strict

Mesos master UI and API

  1. Create the permission.

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    -H  'Content-Type: application/json' \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:mesos \
    -d '{"description":"Grants access to the Mesos master API/UI and task details"}'
    
  2. Grant the permission to a user (<user-name>).

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:mesos/users/<user-name>/full
    

    Tip: To grant this permission to a group instead of a user, replace /users/<user-name> with /groups/<group-name>.

  3. You can send the URL of the Mesos UI for DC/OS to the user: http://<master-public-ip>/mesos/.

Mesos agent API for accessing task sandboxes and logs, and task exec

  1. Create the permission.

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    -H 'Content-Type: application/json' \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:slave \
    -d '{"description":"Grants access to the Mesos agent API/UI and task details such as logs"}'
    
  2. Grant the permission to a user (<user-name>).

    curl -X PUT --cacert dcos-ca.crt \
    -H "Authorization: token=$(dcos config show core.dcos_acs_token)" \
    $(dcos config show core.dcos_url)/acs/api/v1/acls/dcos:adminrouter:ops:slave/users/<user-name>/full
    

    Tip: To grant this permission to a group instead of a user, replace /users/<user-name> with /groups/<group-name>.