Palette Global and Custom Resource Roles
Palette support two types of resource roles, global resource roles and custom resource roles:
- 
Global Resource Roles are a set of roles built in and available to you. 
- 
Custom Resource Roles, are roles you can create in Palette using a set of permissions and operations. 
To learn how to create a custom role. Review the Create Custom Role guide.
Palette Global Resource Roles
Palette provides the following built-in global resource roles:
- 
- 
Resource Cluster Admin 
- 
Resource Cluster Editor 
- 
Resource Cluster Viewer 
 
- 
- 
- 
Resource Cluster Profile Admin 
- 
Resource Cluster Profile Editor 
- 
Resource Cluster Profile Viewer 
 
- 
Cluster
| Role Names | Description | 
|---|---|
| Resource Cluster Admin | A cluster admin in Project scope has all the privileges related to cluster operation | 
| Resource Cluster Editor | A cluster editor in Project scope has the privileges to update, delete,get and list cluster resources. This role is not privileged for cluster creation | 
| Resource Cluster Viewer | A cluster viewer in Project scope is a read-only privilege to cluster operations | 
- Resource Cluster Admin
- Resource Cluster Editor
- Resource Cluster Viewer
Resource Cluster Admin
| resourceKeys | Operations | 
| Create | Delete | Get | List | Update | Import | Publish | Backup | Restore | |
|---|---|---|---|---|---|---|---|---|---|
| cloudaccount | √ | √ | |||||||
| cloudconfig | √ | √ | √ | √ | √ | ||||
| cluster | √ | √ | √ | √ | √ | √ | |||
| clusterProfile | √ | √ | |||||||
| clusterRbac | √ | √ | √ | √ | √ | ||||
| dnsMapping | √ | √ | √ | √ | √ | ||||
| edgehost | √ | √ | √ | √ | √ | ||||
| location | √ | √ | √ | √ | √ | ||||
| machine | √ | √ | √ | √ | √ | ||||
| macro | √ | √ | √ | √ | √ | ||||
| packRegistry | √ | √ | |||||||
| privateGateway | √ | √ | |||||||
| sshKey | √ | √ | √ | √ | √ | 
Resource Cluster Editor
| resourceKeys | Operations | 
| Create | Delete | Get | List | Update | Import | Publish | Backup | Restore | |
|---|---|---|---|---|---|---|---|---|---|
| cloudaccount |