Permissions for Aiven for DataHub features
The following roles and permissions are required for specific Aiven for DataHub features.
View all roles and permissions for Aiven organizations and projects.
| Action | Required roles and permissions |
|---|---|
| Add and remove Aiven service connectors | For the DataHub service: operator, admin, role:project:admin, role:organization:admin, or project:integrations:write. For the service you are connecting, you must have permission to create service users: role:project:admin, role:project:manager, or service:users:write. |
| View DataHub UI connection information including: URL, username, and password | admin, operator, developer, role:organization:admin, service:secrets:read, service:users:write Users with read_only, role:project:read, role:project:admin, or other service permissions can view the URL, but not the password. |
Edit application environment variables to:
| admin, operator, role:project:admin, role:organization:admin, role:services:maintenance, role:services:recover, project:services:write, or service:configuration:write To edit the variables in the Aiven Console, users also need to have access to read secrets through one of the following permissions: admin, operator, role:organization:admin, or service:secrets:read.The developer role can view secret values, but cannot change them. |
| Rotate secrets | admin, operator, or role:organization:admin |