Role-Based Access Control (RBAC) Requirements for Triggering Disaster Recovery Failover | Tanzu Hub
search cancel

Role-Based Access Control (RBAC) Requirements for Triggering Disaster Recovery Failover | Tanzu Hub

book

Article ID: 454377

calendar_today

Updated On:

Products

VMware Tanzu Platform - Hub

Issue/Introduction

When configuring and managing Disaster Recovery (DR) for Tanzu Hub environments, organizations often need clarity on which specific roles have the authorization to trigger a failover.

Specifically, administrators frequently ask if triggering a failover is strictly an Admin-only operation, or if it can be securely delegated to an Organization Group (OrgGroup) Manager. This article serves as a supplementary technique guide to the official documentation on Performing a Failover.

 

Environment

Tanzu Hub

Tanzu Platform for Cloud Foundry (TPCF)

Cause

Clarification is required around RBAC rules for failover operations to ensure that delegation of DR responsibilities aligns with the architectural security constraints of the platform.

Resolution

An OrgGroup Manager is authorized and permitted to trigger a failover. This operation is not restricted exclusively to Administrators.

Allowing OrgGroup Managers to trigger failovers intentionally aligns with the existing permissions they hold within the platform's creation and management flows. Because an OrgGroup Manager already has the foundational permissions to:

  • Create spaces

  • Set topology with an active region

  • Remove regions

It is logically consistent for them to also have the ability to initiate a failover between those regions. Restricting this action solely to Administrators would disrupt the standard operational workflow for OrgGroup Managers.

For step-by-step instructions on executing the failover process, please refer to the official documentation: Perform a Failover.

 

Additional Information

This article serves as a supplementary technique guide to the official documentation. For complete, step-by-step instructions on executing the failover process, please refer to the official Broadcom documentation: