Skip to content
01

Access layer

Identity & UI

The Access layer is the operator front door — one PatternFly console where identity, roles, and day-to-day workflows meet.

Operators work in a single PatternFly interface with Keycloak OIDC or local authentication and object-level RBAC

PatternFlyKeycloakOIDCLocal authRBAC

How requests move

  1. 01

    Operator opens the console

  2. 02

    Identity is verified (OIDC or local)

  3. 03

    RBAC scopes what the session can touch

  4. 04

    Requests reach the control plane APIs

What this layer does

  • Unified PatternFly console for all operator workflows

  • Keycloak OIDC or local authentication without cloud lock-in

  • Object-level RBAC for hosts, jobs, credentials, and reports

  • Role-aware chrome so privileges stay visible during work

Security and infrastructure teams sign in through Keycloak OIDC or a local account, then work inside a single PatternFly shell instead of juggling separate tools.

Object-level RBAC decides who can see hosts, jobs, credentials, and reports, so sensitive inventory stays scoped to the right roles.

This layer keeps the product usable under pressure: searchable navigation, clear role badges, and a consistent operator experience across every module.