AI Registry permissions

AI Regsitries permissions for the following actions are separate from workbench permissions, but they are inherited from environment level workbench permissions.

  • create
  • delete
  • getKubeconfig
  • grant/list/revoke access

Therefore, if you have the MLAdmin role on an environment, you can perform these actions for AI Registries, but an MLUser cannot.

Remote access to a AI Registries works similarly to workbench remote access. In addition to AI Regsitry, but an MLUser cannot.

Remote access to a AI Regsitry works similarly to workbench remote access. In addition to downloading the kubeconfig file, you need to use Grant/List/RevokeModelRegistryAccess endpoints to manage what cloud user identity can access the Kubernetes cluster using your cloud credential.