DevOps Users with 'Build and Deploy Security' Administrator Role unable to access Collections in Prisma Cloud Compute

DevOps Users with 'Build and Deploy Security' Administrator Role unable to access Collections in Prisma Cloud Compute

1042
Created On 05/10/22 03:38 AM - Last Modified 07/13/23 09:17 AM


Symptom


  • DevOps Users are granted access to “Build and Deploy Security” Permission Group. 
  • With this, Users are able to access Compute > Monitor > Vulnerabilities > Images > CI section and view all the Scan Results.
  • However, Users are unable to filter the scan results based on the Collections created. 
  • Searching for a Collection returns 'No Such Value' message while typing in an existing legitimate Collection manually with the Collections Column always empty.
Example
  • User with 'System Admin' Role can filter by existing Collection 'appid' under Compute > Monitor > Vulnerabilities > Images > CI.
Screenshot 2022-05-10 at 12.47.26 PM.png
 
  • However, User with 'Build and Deploy Security' Role unable to filter the scan results based on the Collections created and receives 'No Such Value' message while typing in existing Collection 'appid' manually with the Collections Column empty.

Screenshot 2022-05-10 at 12.51.11 PM.png
 


Environment


  • Prisma Cloud Enterprise Edition (SAAS)


Cause


  • The Desired Functionality is currently not supported with Collections created inside the Compute Console.


Resolution


  • Create a Resource List (of type Compute Access Group).
Settings > Resource Lists > Add Resource List > Compute Access Group > Specify the filters > Save.

Screenshot 2022-05-10 at 6.34.32 PM.png


Additional Information


  • It also recommend to create a Collection similar to the Resource List with the same conditions and use Resource Lists for Access Control and Collections for Vulnerability Policy Rules.

 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpVZCA0&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail