A RightBundle groups a set of custom rights into a named bundle that organisational administrators can use to compose roles. Unlike GlobalRole, a RightBundle is not automatically assigned to any role - it is a palette of rights made available to administrators for manual inclusion in their custom roles.
| Field | Type | Required | Description |
|---|---|---|---|
name |
string | Yes | Display name of the right bundle in VCF Automation |
description |
string | No | Human-readable description |
rights |
[]string | No | List of right identifiers to include |
scope |
ResourceScope | No | Controls which tenant organisations can see the bundle |
Rights are typically RDE-based or custom rights introduced by the service:
broadcom:arcturusProject: Viewbroadcom:arcturusProject: Modifybroadcom:arcturusProject: Full Controlscope:
allTenants: true # make available to all organisations
| Field | Type | Description |
|---|---|---|
status |
string | Healthy, Busy, Unhealthy, Maintenance |
message |
string | Human-readable status message |
externalId |
string | VCF Automation right bundle ID (URN) |
CR created
│
▼
Busy - creating right bundle in VCF Automation
│ Resolving right identifiers
▼
Busy - publishing bundle to tenant organisations per scope
│
▼
Healthy - bundle created, externalId populated
│
├─ rights or scope updated
│ │
│ ▼
│ Busy - updating bundle
│ │
│ ▼
│ Healthy
│
└─ CR deleted
│
▼
Busy - removing bundle from VCF Automation
│
▼
CR removed
Unhealthy.apiVersion: services.vcfa.broadcom.com/v2
kind: RightBundle
metadata:
labels:
services.vcfa.broadcom.com/name: arcturus-rights
spec:
name: arcturusRightsBundle
description: Custom rights for Arcturus registry management
rights:
- 'broadcom:arcturusProject: View'
- 'broadcom:arcturusProject: Modify'
- 'broadcom:arcturusProject: Full Control'
- 'broadcom:arcturusUser: View'
- 'broadcom:arcturusUser: Modify'
scope:
allTenants: true