Skip to main content
Version: v45

Managing Roles

You can create, edit, and remove roles on Administration → Roles. Select a role to view its members and the targets they can access.

A role includes the following settings:

SettingPurpose
RulesDefine filters that determine role membership.
PermissionsSpecify which management and viewing actions role members can perform.
SSH OptionsSpecify the SSH options available to role members.
Contextual RestrictionsRestrict when and from which client addresses the role is valid.
Principal KeysProvide cryptographic keys that allow role members to connect using Public-Key Authentication.

For more information on granting access to target hosts, see Granting Access to Hosts.

Configuring Role Permissions and Address Restrictions​

Role changes take effect within 1–5 minutes.

Settings pages in the PrivX Web UI require both viewing and management permissions. For example, accessing Administration → Roles requires the roles-view and roles-manage permissions.

Before configuring Allowed remote addresses, ensure that the X-Forwarded-For header contains the relevant client IP addresses. If the header contains multiple addresses, configure strip_how_many_x_forwarded_for_client_ips in /opt/privx/etc/shared-config.toml to select which address to use.