User Administration
Invite and maintain local users, reset credentials, assign roles, and distinguish current capabilities from planned service accounts.
Gameplane has no service accounts or API tokens yet; machine-to-machine tokens are planned for v1.1. Until then, give automation its own local user with the narrowest role that works, and never share a person’s login.
Invite a local user
Create a unique identity, secure initial credential, and the minimum global role; add per-server collaboration separately.
New users start with a primary role applied cluster-wide. The three built-in roles are:
- Admin — full access to users, servers, templates, backups, cluster settings, and audit logs
- Operator — manage servers and backups; cannot create/edit users or templates
- Viewer — read-only access to servers, backups, and status
You can refine permissions per namespace (e.g., restrict an operator to a specific game project) using per-namespace role bindings in the Role Bindings section of the user’s card.
Edit roles and reset credentials
Role changes affect global authorization; local and OIDC credentials have different owners.
To reset a local user’s password:
- Find the user in the dashboard Users page
- Click the user card to open details
- Tap Reset Password and enter a new 12+ character value
- The user can log in with the new password immediately
For OIDC users:
- Password resets happen at the identity provider, not in Gameplane
- MFA and account disablement are provider-controlled
- The user’s role and email in Gameplane mirror the provider’s state
Users who log in via OIDC have their role determined by:
- Per-provider group mappings configured under Admin Settings → Authentication, re-evaluated against the user’s IdP groups on each login
- Helm-seeded group mappings (
api.oidc.groupsClaim,api.oidc.roleMappings) for the Helm-configured provider, from v0.3.0; an admin can override them in the dashboard - Manual assignment when no group mapping is configured: new OIDC users get the default role (
viewer) and an admin promotes them
Review lifecycle and availability
Audit access changes and remove dormant roles/collaboration; treat service accounts as version-dependent until shipped.
Periodically review:
- Active users — remove unused accounts to reduce the attack surface
- Role changes — audit the role history in the Audit & Observability logs
- Per-namespace bindings — clean up stale role bindings if a user’s scope narrows
- Providers — verify OIDC providers are still responsive; expired provider certificates log an error in the system log
USER LIFECYCLE
See also
- Users, Auth & RBAC — Overview of authentication and role-based access control
- Permission Catalog — Detailed permission definitions and role matrix
- Audit, Observability & Admin — Monitor user actions and system events