Feature Request: Layer-Scoped RBAC for Multi-Tenant Deployments (Horizon UI) #14107
aliebrahimy
started this conversation in
Ideas
Replies: 1 comment 8 replies
8 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment




Uh oh!
There was an error while loading. Please reload this page.
Hi Horizon UI team,
First, thank you for the excellent work on Horizon UI. We are deploying it in a multi-tenant environment with multiple Kubernetes clusters and Docker-based services, and we use OAP service groups (via the group::service naming convention) to logically separate services by team (e.g., payments::, risk::).
Current Limitation:
As documented, Horizon's RBAC operates at the verb level (e.g., metrics:read, traces:read) and does not support resource-level restrictions. A user with the viewer role can see all Layers in the sidebar and access metrics for all services, regardless of which group they belong to.
While splitByServiceGroup in layer templates provides a UI grouping, it is a presentation feature and does not enforce any access control. A curious user can simply switch the group dropdown and see other teams' services.
Use Case:
We want to assign users to a role that only grants access to a specific Layer (or a set of Layers). For example:
A user with payments-viewer role should only see the PAYMENTS layer in the sidebar and access its metrics/traces/logs.
The same user should be unable to query metrics for the RISK layer, even if they know the correct MQE expression or URL.
Proposed Feature:
We would like to request Layer-Scoped RBAC where grants can be narrowed to specific Layers. Some possible syntax options:
metrics:read:PAYMENTS (grant read access only to the PAYMENTS layer)
traces:read:PAYMENTS,RISK (multiple layers)
Or a separate allowedLayers array per role in horizon.yaml:
rbac: roles: payments-viewer: - metrics:read - traces:read - logs:read allowedLayers: ["PAYMENTS"]mpact:
This would enable secure multi-tenant deployments where teams only see their own observability data, aligning Horizon UI with enterprise access control requirements.
Thank you for considering this feature. We are happy to provide more details or test any prototype.
All reactions