New Relic ユーザー管理のコンテキストでは、権限とは New Relic で実行できる特定のタスクのことです。さまざまな権限が、あらかじめ構築されたロールに含まれています (たとえば、 標準ロール を参照してください)。権限の例をいくつか示します。
APMアプリの設定を表示する機能 アラート条件を変更する データ保持期間の設定を管理する 組織レベルの認証ドメインを作成する 個々のフリートを特定のリソースにデプロイする 3 つの異なるスコープでカスタム ロールを作成し、任意の数の権限を追加できます。
組織スコープの権限 : 組織全体の管理機能用 (Identity and Access Management、 New Relic One、 APIキー、セキュリティなど)アカウントスコープの権限 : 特定のアカウント内のプラットフォーム機能用 ( APM 、 Browser 、インフラストラクチャ、アラートなど)エンティティスコープの権限 :特定のリソースへのきめ細かなアクセスロールにどのような権限があるかを確認するには、ユーザー管理 UI に移動し、特定のロールを表示します。 この UI を見つけるには: one.newrelic.com から右下のユーザー メニューを クリックし、次にAdministration > Access management > Roles に移動します。
権限に関する注意事項 制限のない New Relic フル プラットフォーム ユーザー (たとえば、 Admin グループのユーザー) は、プラットフォームのすべての機能を使用できます。New Relic で実行できるタスクの多くは、 permissionsとして利用できます (ただし、すべてではありません)。カスタム ロールにこれらを追加または削除することができ、またこれらの権限を使用して標準ロール を区別します。表示され、選択できる権限は、一般的なユーザー管理タスクに最も役立つと思われる権限です。
表示されず、選択可能な権限として利用できない New Relic 機能は多数あります。たとえば、あらゆるユーザーとしてアクセスでき、私たちが公開する権限によって制限されないさまざまな UI ページがあります。
ヒント 権限は、 capabilities と呼ばれることもあります。
権限に関するその他の重要な点は次のとおりです。
A user's user type must also allow access. New Relic 機能へのユーザーのアクセスは、ユーザー タイプと割り当てられたロールの両方によって制御されます。 詳細については、 「ユーザー アクセス」 を参照してください。Some permissions overlap in functionality. UI で一部の権限チェックボックスを選択すると、他のボックスが自動的にオンまたはオフになるのはこのためです。Permissions don't affect querying of data. ほとんどの権限は New Relic UI および API エクスペリエンスに適用され、データのクエリには適用されません。 たとえば、権限によってAPM UI へのアクセスが制限されている場合でも、そのアカウントにアクセスできれば APM データをクエリできます。 一部のプロジェクトまたはユーザーに対してより明確なデータ境界が必要な場合は、データを異なるアカウント にセグメント化できます。ユーザー権限を制御する主な方法の詳細については、 「 ユーザー管理の概念 」 を参照してください。
事前に構築された役割 事前に構築されたロールには、さまざまな権限のグループがあります。役割の詳細については、 こちらをご覧ください。
権限の定義 UI にアクセスして、事前に構築された各ロールの権限を表示できます。UI の左下隅で自分の名前をクリックしてユーザー メニューを開き、 Administration > Access management > Roles に移動します。
UI には、次のようなすべてのロールの権限に関する詳細情報が表示されます。
全製品アドミン 標準ユーザー 読み取り専用 組織内のすべてのカスタムロール アクセス管理 UI には、各ロールの最新の権限の詳細が表示されます。
Identity and Access Management These organization-scoped permissions pertain to managing users, groups, roles, and authentication domains within your organization:
Accounts : Create and manage accounts within your organization.Authentication Domains : Configure how users are provisioned and authenticated.Data Access Policies : Create and manage policies that control access to log data partitions.Grants : Create and manage access grants that link groups to roles over specific targets.Groups : Create and manage user groups within authentication domains.Roles : Create and manage custom roles with specific permissions.Users : Add, remove, and manage users within your organization.API keys These permissions pertain to creating and managing our API keys :
APM These permissions pertain to our APM agents and associated features:
Browser These permissions pertain to ブラウザ監視 :
Data retention Insights event retention : This governs the ability to manage data retention values within the bounds of a contract for specific data namepsaces.Incident workflows Workflows : relates to a preview workflows feature that will likely be deprecated in 2022.Infrastructure Cloud integrations : relates to cloud integrations .Filter sets : relates to filter sets . This feature is in process of being deprecated and is only available on the infrastructure Events and Inventory UI pages.Insights Insights is the original name for a product that had features related to custom data ingest, custom queries, custom charts, and custom dashboards. Permissions include:
Any dashboard : relates to the ability to delete any dashboard in an account.
Data sources : relates to a now deprecated UI that allowed for controlling what data was reported to New Relic.
Events to metrics : this governs:
Insert keys : relates to our mostly deprecated Insights insert key (a license key is preferred).
NRQL drop rules : relates to dropping data with drop rules .
Query keys : relates to our mostly deprecated Insights query key (the ユーザーキー is preferred).
Logs Data partition rules : relates to data partitions .Live archives configuration : relates to configuring live archives retention for logs.Live archives query : relates to querying logs stored in live archives .Obfuscation rules : relates to log obfuscation .Parsing rules : relates to log parsing .Pipeline configuration : relates to configuring the log data pipeline. Currently this governs log patterns .Public saved views : relates to saved views that are public.New Relic One These are assorted permissions related to basic features of the New Relic platform (sometimes referred to as New Relic):
Entities : relates to creating and deleting New Relic-monitored entities .Entity relationships : relates to entity relationships .Golden metrics : relates to golden metrics (key metrics) in curated user experiences.Nerdpacks : relates to New Relic apps .NRQL lookups : relates to the ability to use lookup tables .Pixie account link : this capability allows the creation of an associated Pixie account when adding Pixie to a cluster from our guided install .Pixie credentials : relates to access of linked Pixie accounts.Pixie live data : enables access to live debugging data in the Kubernetes cluster explorer .Repositories : relates to creating and deleting New Relic-monitored repositories (used by features like New Relic CodeStream ).Tags : relates to platform tagging .Workloads : relates to workloads .Security Vulnerabilities : refers to the ability to view and manage vulnerabilities detected in entities.