Authorization: Security Clearance and Permissions
-
X.509 certificates are used for authentication, validating that users are who they say they are.
Once a connection is authenticated, RavenDB uses the certificate for authorization as well. -
Each certificate is associated with a security clearance and access permissions per database.
-
It is the administrator's responsibility to generate client certificates and assign permissions.
Read more on the Certificate Management page. -
A client certificate's security clearance can be one of the following: Cluster Admin, Operator, or User.
-
In this article:
Cluster Admin
Cluster Admin is the highest security clearance, with no restrictions.
A Cluster Admin certificate has admin permissions to all databases, and can also modify the
cluster itself.
The following operations are allowed only for Cluster Admin certificates:
- All cluster operations
- Manage
Cluster Admincertificates - Replace and renew server certificates
- Use the Admin JS Console
- Activate or update the license
- Get SNMP used OIDs
Operator
A client certificate with an Operator security clearance has admin access to all databases but
cannot modify the cluster. For example, it cannot add, remove, promote, or demote cluster nodes.
This clearance is useful in a hosted solution such as RavenDB Cloud.
If you are running on your own machines, you will typically use Cluster Admin or User instead.
The following operations are allowed for both Operator and Cluster Admin certificates, but
not for User certificates:
- Operations on databases (put, delete, enable, disable)
- Manage
OperatorandUsercertificates - Enable and disable an ongoing task
- Define External Replication
- Create and delete RavenDB ETL and SQL ETL
- Migrate databases
- View cluster observer logs
- View admin logs
- Gather local and cluster debug info (process, memory, cpu, threads)
- Use smuggler
- Use the traffic watch
- Put cluster-wide client configuration (Max number of requests per session, Read balance behavior)
- Get the database record
- Manage database groups in the cluster
- Restore databases from backup
- Perform database and index compaction
- Get server metrics (request/sec, indexed/sec, batch size, etc.)
- Get remote server build info
User
A client certificate with a User security clearance cannot perform any admin operations at the
cluster level.
Unlike the other clearance levels, a User certificate can be granted a different access level for
each database.
These access levels are, from highest to lowest:
- Admin
- Read/Write
- Read Only
If no access level is defined for a particular database, the certificate does not grant access to that database at all.
When a database is deleted, RavenDB removes its name from the permissions of every client certificate that was granted access to it.
If you later re-create a database with the same name, reassign the relevant permissions
to each certificate that needs access to it.
Admin
The following operations are permitted at the Admin access level but not for Read/Write or
Read Only:
- Operations on indexes (put, delete, start, stop, enable and disable)
- Solve replication conflicts
- Configure revisions and delete revision documents
- Define expiration
- Create backups and define periodic backups
- Operations on connection strings (put, get, delete)
- Put client configuration for the database (Max number of requests per session, Read balance behavior)
- Get transaction info
- Perform SQL migration
Read/Write
A User certificate with a Read/Write access level can perform all operations except those
listed above in the Admin and Operator sections.
-
JavaScript static indexes are permitted by default for User certificates with Read/Write access.
To configure a server or database so that only clients with Admin access can deploy JavaScript static indexes, set Indexing.Static.RequireAdminToDeployJavaScriptIndexes totrue. -
Data subscriptions access
AUsercertificate with aRead/Writeaccess level can create, edit, delete, and enable or disable data subscriptions.
Subscriptions are an exception among ongoing tasks: managing other ongoing tasks requires a higher access level, while subscriptions can be managed withRead/Writeaccess.
Read Only
The Read Only access level allows clients to:
- Read data from a database, but not write or modify data.
- Consume data subscriptions as subscription workers.
- Query the databases configured in the client certificate.
If no existing index satisfies this query, an auto-index may be built.
The following operations are forbidden:
- Creating documents or modifying existing documents
- Changing any configurations or settings
- Creating or modifying ongoing tasks
- Defining static indexes (the database will create auto-indexes if no existing index satisfies a query)