Space access controls who can enter and use a deployed Studio or Fabric Space.
Space access is separate from K2cloud Orchestrator access:
A user who only needs access to a Space does not need access to K2cloud Orchestrator.
Users access an authorized Space directly through its Space URL.
When a user opens the Space URL, the user is redirected through the configured K2cloud identity flow. After authentication, the user's authorization for the Space is evaluated.
Depending on the Space and the user's permissions, access can include applications and capabilities such as:
Successful authentication alone does not grant access. The authenticated user must also have the appropriate authorization for the Space.
Space access is controlled through Fabric roles.
Common runtime roles include:
space_admin,space_user,The roles assigned to a user determine the applications and capabilities available within the Space.
For detailed authorization-design guidance, see Roles and Permissions.
Creating a Space through K2cloud Orchestrator does not automatically make the person who created it a Space Administrator.
K2cloud Orchestrator lifecycle privileges and Fabric runtime authorization are separate.
For example, a Project Manager can:
The developers can then access the Studio Space directly without requiring the cloud_user role or access to K2cloud Orchestrator.
Initial Space authorization must be established by an appropriately authorized administrator.
Space roles and permissions are managed through the Space's Web Admin interface.
Web Admin is used to administer Fabric runtime authorization, including the roles and permissions applicable within the Space.
K2cloud Orchestrator does not replace the Fabric runtime permission model.
The operational boundary is:
K2cloud Orchestrator
↓
Space lifecycle management
Fabric Web Admin
↓
Space runtime authorization
This separation allows responsibility for operating the K2cloud environment to remain independent from responsibility for administering or using applications within a Space.
In federated environments, customer IdP groups are mapped through K2cloud identity federation to Fabric roles.
The typical authorization chain is:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
Space Runtime Authorization
The customer manages user membership in its enterprise IdP groups. The federation mapping associates those groups with the appropriate Fabric roles.
If the mapping is incomplete or incorrect, a user may successfully authenticate but still be unable to access the Space or the expected functionality.
For more information, see Identity Federation.
TDM-enabled Spaces can require additional TDM authorization.
The authorization chain can include:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
TDM Permission Group
A user can therefore be authorized to access the Fabric Space but still lack the permissions required to use specific TDM capabilities.
Fabric roles and TDM permission groups should be assigned according to the user's responsibilities.
Space access does not grant source-code contribution rights.
Git repository access is managed independently through the Git platform.
For example:
K2cloud does not manage Git users or repository permissions.
Space access should reflect what the user needs to do.
Do not grant K2cloud Orchestrator access simply because a user requires access to a Space.
Space access controls who can enter and use a deployed Studio or Fabric Space.
Space access is separate from K2cloud Orchestrator access:
A user who only needs access to a Space does not need access to K2cloud Orchestrator.
Users access an authorized Space directly through its Space URL.
When a user opens the Space URL, the user is redirected through the configured K2cloud identity flow. After authentication, the user's authorization for the Space is evaluated.
Depending on the Space and the user's permissions, access can include applications and capabilities such as:
Successful authentication alone does not grant access. The authenticated user must also have the appropriate authorization for the Space.
Space access is controlled through Fabric roles.
Common runtime roles include:
space_admin,space_user,The roles assigned to a user determine the applications and capabilities available within the Space.
For detailed authorization-design guidance, see Roles and Permissions.
Creating a Space through K2cloud Orchestrator does not automatically make the person who created it a Space Administrator.
K2cloud Orchestrator lifecycle privileges and Fabric runtime authorization are separate.
For example, a Project Manager can:
The developers can then access the Studio Space directly without requiring the cloud_user role or access to K2cloud Orchestrator.
Initial Space authorization must be established by an appropriately authorized administrator.
Space roles and permissions are managed through the Space's Web Admin interface.
Web Admin is used to administer Fabric runtime authorization, including the roles and permissions applicable within the Space.
K2cloud Orchestrator does not replace the Fabric runtime permission model.
The operational boundary is:
K2cloud Orchestrator
↓
Space lifecycle management
Fabric Web Admin
↓
Space runtime authorization
This separation allows responsibility for operating the K2cloud environment to remain independent from responsibility for administering or using applications within a Space.
In federated environments, customer IdP groups are mapped through K2cloud identity federation to Fabric roles.
The typical authorization chain is:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
Space Runtime Authorization
The customer manages user membership in its enterprise IdP groups. The federation mapping associates those groups with the appropriate Fabric roles.
If the mapping is incomplete or incorrect, a user may successfully authenticate but still be unable to access the Space or the expected functionality.
For more information, see Identity Federation.
TDM-enabled Spaces can require additional TDM authorization.
The authorization chain can include:
Customer IdP Group
↓
K2cloud Identity Federation
↓
Fabric Role
↓
TDM Permission Group
A user can therefore be authorized to access the Fabric Space but still lack the permissions required to use specific TDM capabilities.
Fabric roles and TDM permission groups should be assigned according to the user's responsibilities.
Space access does not grant source-code contribution rights.
Git repository access is managed independently through the Git platform.
For example:
K2cloud does not manage Git users or repository permissions.
Space access should reflect what the user needs to do.
Do not grant K2cloud Orchestrator access simply because a user requires access to a Space.