Groups

This page describes IAM groups in Lenses.

Groups collect users and service accounts. Groups are granted permissions via roles.

Assigning Users to Groups

Users can be assigned to groups in two ways:

  1. Manual

  2. Linked from the groups provided by your SSO provider

This behaviour can be toggled in your organisation settings. To control the default, set the following in HQ config.yaml.

users_group_membership_management_mode: [manual|sso]

Groups can be defined with the following metadata:

  1. Colour

  2. Description

Each group has a resource that uniquely identifies it across an HQ installation.

Create a Group

To create a group, go to IAM → Groups → New Group. Then assign members, service accounts, and roles.

IAM Groups

You can also manage groups via the CLI and YAML, for CI/CD automation.

Last updated

Was this helpful?