Managing Roles
You can create, edit, and remove roles on Administration → Roles. Select a role to view its members and the targets they can access.
A role includes the following settings:
| Setting | Purpose |
|---|---|
| Rules | Define filters that determine role membership. |
| Permissions | Specify which management and viewing actions role members can perform. |
| SSH Options | Specify the SSH options available to role members. |
| Contextual Restrictions | Restrict when and from which client addresses the role is valid. |
| Principal Keys | Provide cryptographic keys that allow role members to connect using Public-Key Authentication. |
For more information on granting access to target hosts, see Granting Access to Hosts.
Configuring Role Permissions and Address Restrictions
Role changes take effect within 1–5 minutes.
Settings pages in the PrivX Web UI require both viewing and management permissions. For example, accessing Administration → Roles requires the roles-view and roles-manage permissions.
Before configuring Allowed remote addresses, ensure that the X-Forwarded-For header contains the relevant client IP addresses. If the header contains multiple addresses, configure strip_how_many_x_forwarded_for_client_ips in /opt/privx/etc/shared-config.toml to select which address to use.