Skip to content

KKP UI: Document Admin Groups for automatic admin privileges - #2262

Open
KhizerRehan wants to merge 1 commit into
kubermatic:mainfrom
KhizerRehan:docs/8205-admin-groups
Open

KKP UI: Document Admin Groups for automatic admin privileges#2262
KhizerRehan wants to merge 1 commit into
kubermatic:mainfrom
KhizerRehan:docs/8205-admin-groups

Conversation

@KhizerRehan

@KhizerRehan KhizerRehan commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

What this PR does / why we need it:

This PR adds documentation for the Admin Groups setting, which automatically grants KKP administrator privileges to members of the configured OIDC groups.

Related PRs:
kubermatic/dashboard#8205

Adds an Admin Groups section to the Administrators page of the Admin
Panel documentation, covering how to configure the setting, how group
names are matched against the upstream OIDC groups, how privileges are
kept in sync, and which users are excluded from automatic promotion.
@kubermatic-bot kubermatic-bot added dco-signoff: yes Denotes that all commits in the pull request have the valid DCO signoff message. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Aug 13, 2026
@kubermatic-bot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign csengerszabo for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ahmadhamzh ahmadhamzh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

few comments PTAL

privileges again once the group is removed from the setting or the user leaves the group.

{{% notice note %}}
Admin Groups are available in the Enterprise Edition only.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is it an EE only ?


![User Accounts](images/admin-groups-user-accounts.png?classes=shadow,border "Groups on the User Accounts Page")

### How the Privileges Are Kept in Sync

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we need to have this section in the docs? I think it’s more technical, and users expect that nothing needs to be done manually.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

could you redo the screenshot with mock users, or blur out the email column.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dco-signoff: yes Denotes that all commits in the pull request have the valid DCO signoff message. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants