Authorization of Cloudera AI Inference service

Cloudera AI Inference service implements role-based access control.

To create an instance of the service in a Cloudera environment, and to perform modifications to the instance, such as the addition of a node group, the user must have the following roles in the environment:
  • EnvironmentAdmin
  • MLAdmin
Model endpoints can be viewed, created, deleted, and modified by users having EnvironmentUser role along with either one of the following roles in the environment:
  • MLAdmin
  • MLUser
  • AIInferenceInstanceAdmin

    This new role enables the administrator to upgrade, delete Cloudera AI Inference service instances, and to create, read, update, and delete all model endpoints.

  • AIInferenceInstanceUser

    This new role enables the user to view, manage, and own endpoints and Cloudera AI Inference service instances.

For information on how to grant the MLUser roles to users/groups, see Granting Cloudera Data Platform Users Access to Cloudera AI Workbenches.