Deployment Architecture

What are the minimum capabilities needed to modify and push config change from Deployment Server?

the_wolverine
Champion

I'd like to have a role which allows a user to manage config changes and deployment (deploy-server) from Splunk deployment server.

I don't think this user needs admin access. I found the following capability in authorize.conf.spec:

[capability::edit_deployment_server]
        * Self explanatory. The deployment server admin endpoint requires this cap for edit.

Is this all that is needed?

1 Solution

the_wolverine
Champion

I have confirmed that the capability is all that is needed to reload deploy-server.

edit_deployment_server = enabled

View solution in original post

hawkdavis
Engager

list_deployment_server capability is all that is needed to reload a deployment server.

0 Karma

the_wolverine
Champion

I have confirmed that the capability is all that is needed to reload deploy-server.

edit_deployment_server = enabled

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...