7610627168
Bring LiteLLM into the two-tier RBAC and map groups to LiteLLM roles. - akP-litellm-admin / akP-litellm-user permission groups (bound to the litellm app for access); added to akR-global-admin / akR-standard-user roles. - Generic per-provider role_mappings: emit an app role claim computed from effective (hierarchical) group membership. LiteLLM: emits `litellm_role` (proxy_admin for akP-litellm-admin, internal_user for akP-litellm-user, else internal_user_view_only); LiteLLM reads it via GENERIC_USER_ROLE_ATTRIBUTE. Validated: plan 5 to add, 3 to change; generated role expression renders correctly.
7 lines
181 B
YAML
7 lines
181 B
YAML
# Role akR-global-admin (name = filename): full admin across all onboarded apps.
|
|
permissions:
|
|
- akP-grafana-admin
|
|
- akP-argocd-admin
|
|
- akP-rancher-admin
|
|
- akP-litellm-admin
|