Allow deletion of a role named "admin" (#69486)

This is a relic of the Teleport 6 days before we added RBAC to OSS
Teleport. Back then, every local user had a role named "admin", and
we had some protection in place preventing that role from being deleted.

Today, no such role exists, but the deletion prevention remains. This
means you can create your own custom role named "admin" and Teleport
won't let you delete it.

Closes #69222
This commit is contained in:
Zac Bergquist
2026-08-10 08:05:22 +00:00
committed by GitHub
parent e0d3c67924
commit 40e6fa0087
2 changed files with 0 additions and 12 deletions
-4
View File
@@ -696,10 +696,6 @@ const (
// SCP is Secure Copy.
const SCP = "scp"
// AdminRoleName is the name of the default admin role for all local users if
// another role is not explicitly assigned
const AdminRoleName = "admin"
const (
// PresetEditorRoleName is a name of a preset role that allows
// editing cluster configuration.
-8
View File
@@ -5875,14 +5875,6 @@ func (a *ServerWithRoles) DeleteRole(ctx context.Context, name string) error {
return trace.Wrap(err)
}
// DELETE IN (7.0)
// It's OK to delete this code alongside migrateOSS code in auth.
// It prevents 6.0 from migrating resources multiple times
// and the role is used for `tctl users add` code too.
if a.authServer.modules.IsOSSBuild() && name == teleport.AdminRoleName {
return trace.AccessDenied("can not delete system role %q", name)
}
return a.authServer.DeleteRole(ctx, name)
}