Model Registry permissions

Model registry permissions for the following actions are separate from workspace permissions, but they are inherited from environment level workspace permissions.

  • create
  • delete
  • getKubeconfig
  • grant/list/revoke access

Therefore, if you have the MLAdmin role on an environment, you can perform these actions for model registry, but an MLUser cannot.

Remote access to a model registry works similarly to workspace remote access. In addition to downloading the kubeconfig file, you need to use Grant/List/RevokeModelRegistryAccess endpoints to manage what cloud user identity can access the Kubernetes cluster using your cloud credential.