Skip to main content

Permissions for Aiven for DataHub features

The following roles and permissions are required for specific Aiven for DataHub features.

View all roles and permissions for Aiven organizations and projects.

ActionRequired roles and permissions
Add and remove Aiven service connectorsFor the DataHub service: operator, admin, role:project:admin, role:organization:admin, or project:integrations:write. For the service you are connecting, you must have permission to create service users: role:project:admin, role:project:manager, or service:users:write.
View DataHub UI connection information including: URL, username, and passwordadmin, operator, developer, role:organization:admin, service:secrets:read, service:users:write

Users with read_only, role:project:read, role:project:admin, or other service permissions can view the URL, but not the password.
Edit application environment variables to:
  • Enable Slack notifications
  • Enable Teams notifications
  • Enable OIDC authentication
  • Reindex search and graph indices
admin, operator, role:project:admin, role:organization:admin, role:services:maintenance, role:services:recover, project:services:write, or service:configuration:write

To edit the variables in the Aiven Console, users also need to have access to read secrets through one of the following permissions: admin, operator, role:organization:admin, or service:secrets:read.

The developer role can view secret values, but cannot change them.
Rotate secretsadmin, operator, or role:organization:admin