LogoLogo
Contact Uscybus.io
Connectware 1.11.0
Connectware 1.11.0
  • Getting Started
    • Cybus Connectware Documentation
    • System Requirements
    • Admin UI
    • Basic Components of Connectware
    • Connecting your First Machine
      • Your First Service Commissioning File
  • Deployment & Configuration
    • Installation & Upgrades
      • Installing Connectware
        • Installing Connectware (Kubernetes)
        • Installing Connectware (Docker)
      • Upgrading Connectware
        • Upgrading Connectware (Kubernetes)
          • Version-Specific Upgrades (Kubernetes)
        • Upgrading Connectware (Docker)
          • Version-Specific Upgrades (Docker)
      • Uninstalling Connectware
        • Uninstalling Connectware (Kubernetes)
        • Uninstalling Connectware (Docker)
      • Licensing
      • Restarting Connectware
    • User Management
      • Users
        • Default Admin User
      • Roles
      • Permissions
      • MQTT User Authentication
      • Adding a MQTT Publish Prefix for Users
      • Multi-Factor Authentication
      • Single Sign-On (SS0)
        • Single Sign-On with Microsoft Entra ID
        • Single Sign-On with LDAP
      • Access Permissions for Admin-UI
        • UI Access
        • Minimum Access Role Pages
    • Services
      • Service Overview
      • Service Resources View
        • Service Links View
        • Servers View
        • Containers View
        • Volumes View
        • Connections View
        • Endpoints View
        • Mappings View
      • Service Details View
      • Service Commissioning Files
        • Version
        • Description
        • Metadata
        • Parameters
        • Definitions
        • Resources
          • Cybus::Connection
          • Cybus::Container
            • Docker Problem with Network Changes
          • Cybus::Endpoint
          • Cybus::File
          • Cybus::IngressRoute
          • Cybus::Link
          • Cybus::Mapping
          • Cybus::Node
          • Cybus::Role
          • Cybus::Server
          • Cybus::User
          • Cybus::Volume
      • Setting Up & Configuring Services
        • Installing Services
        • Enabling Services
        • Updating Services
        • Disabling Services
        • Deleting Services
      • FlowSync
        • Example 1 - Node with Transaction Mode (HTTP)
        • Example 2 - Node Responds (HTTP)
        • Example 3 - Node with Error (HTTP)
        • Example 4 - Node with Timeout Error Code & Error Message (HTTP)
        • Example 5 - Full Transactional Data Flow (HTTP)
        • Example 6 - Full Transactional Data Flow (OPC UA)
      • ServiceID
      • Inter-Service Referencing
      • Deviations
      • Service Logs
        • Logs of Individual Services
        • Logs of All Services
      • Rule Engine
        • Data Processing Rules
        • Rule Sandbox
      • Shared Subscriptions
        • Setting Up Shared Subscriptions
    • Agents
      • Agents View
      • Installing Agents
        • Installing Agents via Docker
        • Installing Agents via Docker Compose
        • Installing Agents via Kubernetes
        • Using Mutual TLS for Agents
      • Registering Agents in Connectware
      • Using Agents
      • Monitoring Agents
      • Agents in Kubernetes
        • Adding Agents Inside your Connectware Installation
        • Remote Agents with the connectware-agent Helm Chart
        • Kubernetes Cluster Requirements for the connectware-agent Helm Chart
        • Installing Connectware Agents using the connectware-agent Helm Chart
        • Installing Connectware Agents without a License Key Using the connectware-agent Helm Chart
        • Upgrading the connectware-agent Helm Chart
        • Uninstalling Connectware agents with the connectware-agent Helm chart
        • Configuration Principles for the connectware-agent Helm Chart
        • Configuring Agents with the connectware-agent Helm Chart
          • Configuring Target Connectware for the connectware-agent Helm Chart
          • Configuring Agent Persistence for the connectware-agent Helm Chart
          • Configuring Compute Resources for the connectware-agent Helm Chart
          • Using a Custom Image Registry for the connectware-agent Helm Chart
          • Configuring Image Pull Policy for the connectware-agent Helm Chart
          • Using Mutual Transport Layer Security (mTLS) for agents with the connectware-agent Helm chart
          • Configuring image name & version for the connectware-agent Helm chart
          • Configuring Environment Variables for the connectware-agent Helm Chart
          • Configuring Labels & Annotations for the connectware-agent Helm Chart
          • Configuring podAntiAffinity for the connectware-agent Helm Chart
          • Assigning Agents to Kubernetes Nodes for the connectware-agent Helm Chart
          • Configuring Security Context for the connectware-agent Helm Chart
          • Controlling the Name of Kubernetes Objects for the connectware-agent Helm Chart
      • Troubleshooting Agents
    • Client Registry
      • Client Registry for MQTT Clients
      • Client Registry via REST API
      • Troubleshooting Client Registry
    • Security
      • TLS Certificates
        • Certificate Requirements
          • Cipher Suites & TLS Versions
        • CA Certificates
          • Certificates View
        • Client Certificates
        • Server Certificates
      • Password Policy Configuration
      • JSON Web Tokens
    • Monitoring
      • Data Explorer
      • Live Data
    • Node-RED Workbench
    • System Status
      • System Container Status
      • Internet Connectivity Status
      • Metrics (Data Points and Messages)
      • Agents Status
      • License Information
      • System Information
    • Backup & Restore
      • Volumes
      • User Database
    • CybusMQ
      • Configuring CybusMQ
    • Connectware on Kubernetes
      • Connectware Helm Chart
      • Resizing Broker Volumes in Kubernetes
      • Configuring Core Services
      • LDAP Authentication
        • Configuring LDAP Authentication
        • Enabling TLS for LDAP Authentication
        • Manual Kubernetes Secret for LDAP Authentication Bind User
        • Customizing the Search Filter for LDAP Authentication
        • Customizing the User RDN for LDAP Authentication
      • Troubleshooting Connectware on Kubernetes
    • Environment Variables
    • Industry Protocol Details
      • ADS
        • ADS Connection Properties
        • ADS Endpoint Properties
      • BACnet
        • BACnet Connection Properties
        • BACnet Endpoint Properties
      • Custom Connectors
        • Developing Custom Connectors
        • Deploying Custom Connectors
        • Using Custom Connectors
      • EtherNet/IP
        • EtherNet/Ip Connection Properties
        • EtherNet/Ip Endpoint Properties
      • FOCAS
        • FOCAS Connection Properties
        • FOCAS Endpoint Properties
      • Hottinger Baldwin Messtechnik (HBM)
        • HBM Connection Properties
        • HBM Endpoint Properties
      • Heidenhain DNC
        • Heidenhain DNC Connection Properties
        • Heidenhain DNC Endpoint Properties
      • HTTP/REST
        • HTTP/REST Connection Properties
        • HTTP/REST Endpoint Properties
      • HTTP Server/Node
        • HTTP Server Properties
        • HTTP Node Properties
      • InfluxDB
        • InfluxDB Connection Properties
        • InfluxDB Endpoint Properties
      • Kafka
        • Kafka Connection Properties
        • Kafka Endpoint Properties
      • Modbus/TCP
        • Modbus/TCP Connection Properties
        • Modbus/TCP Endpoint Properties
      • MQTT
        • MQTT Connection Properties
        • MQTT Endpoint Properties
      • MSSQL
        • Mssql Connection Properties
        • Mssql Endpoint Properties
      • OPC DA
        • OPC DA Connection Properties
        • OPC DA Endpoint Properties
      • OPC UA
        • OPC UA Client
          • OPC UA Client Connection Properties
          • OPC UA Client Endpoint Properties
        • OPC UA Server
          • OPC UA Server Properties
          • OPC UA Node Properties
        • OPC UA Object Types
        • OPC UA Server References
          • OPC UA Reference Node
          • OPC UA Object Node
      • Siemens SIMATIC S7
        • Siemens S7 Connection Properties
        • Siemens S7 Endpoint Properties
      • Shdr
        • Shdr Connection Properties
        • Shdr Endpoint Properties
      • SINUMERIK
        • SINUMERIK Connection Properties
        • SINUMERIK Endpoint Properties
      • SOPAS
        • SOPAS Connection Properties
        • SOPAS Endpoint Properties
      • SQL
        • SQL Connection Properties
        • SQL Endpoint Properties
      • Werma WIN Ethernet
        • Werma WIN Ethernet Connection Properties
        • Werma WIN Ethernet Endpoint Properties
      • Systemstate
        • Systemstate Endpoint Properties
  • Reference
    • API Reference
      • User Management (API)
      • Client Registry (API)
      • Services (API)
      • Resources (API)
      • System Status (API)
      • Resource Status Tracking (HTTP API)
      • Industry Protocol Details (API)
    • Changelog
Powered by GitBook
LogoLogo

Cybus

  • Terms and Condition
  • Imprint
  • Data Privacy

© Copyright 2025, Cybus GmbH

On this page
  • Users View
  • Adding New Users
  • Default Mode
  • Advanced Mode
  • Deleting Users
  • Changing User Names
  • Adding Roles to Users
  • Deleting Roles from Users
  • Assigning Individual Permissions to Users
  • Deleting Permissions from User
  • Changing User Passwords

Was this helpful?

  1. Deployment & Configuration
  2. User Management

Users

Create and manage users, their roles, and permissions.

PreviousUser ManagementNextDefault Admin User

Last updated 1 day ago

Was this helpful?

In Connectware, users are a known identity (person or software/hardware agent) with associated data permissions and/or administrative access. This chapter guides you through the user management in Connectware, from creating new users to assigning permissions.

Before creating individual users, establish a clear role-based access control strategy by defining roles that correspond to job functions within your organization. This approach simplifies user management and ensures consistent application of security policies.

During installation, Connectware creates a default administrator user to ensure immediate system access. This user is named admin and has the connectware-admin role assigned to provide comprehensive permissions. For more information, see .

Users View

The Users View provides a comprehensive view of all users in Connectware, including their assigned roles and permissions.

  • To open the Users View, click User in the navigation panel.

Adding New Users

  1. In the Users View, click Add User to open the Create User dialog.

  1. Do one of the following:

Default Mode

  1. In the Create User dialog, enter the username, password, and password confirmation.

  2. Optional: To assign a set of pre-defined roles to the user, click the Roles field and select a role. You can repeat this step to assign multiple roles.

  3. Click Create. The dialog will close and the new user will be added to the overview table.

Advanced Mode

In the advanced mode, you can assign a set of pre-defined roles to the user and/or individual permissions.

  1. In the Create User dialog, enter the username, password, and password confirmation.

  2. Activate Advanced Mode.

  1. Optional: To assign a set of pre-defined roles to the user, click the Roles field, select a role, and click Add. You can repeat this step to assign multiple roles.

  2. Optional: To assign individual permissions, click the + button to open the Add Permission dialog.

    • Select the permission type: HTTP for accessing the REST API using HTTP clients or MQTT for accessing MQTT topics on CybusMQ.

    • In the Endpoint field, enter the resource path, which follows MQTT topic conventions. The specified topic can be a single topic or a wildcard. HTTP permissions for the resource path follow an MQTT topic structure. This means that you can use wildcards (# and +) in valid expressions, and paths must start with a leading slash (/).

    • Select the access type: read, write, or both.

    • Click Add to add the permission.

  1. Click Create. The dialog will close and the new user will be added to the overview table.

Deleting Users

You can delete users that are no longer needed.

Deleting a user is permanent and cannot be undone. Before proceeding, ensure that you have backed up any important user-specific configurations or transferred necessary permissions to other users.

  1. In the navigation panel, click User.

  2. In the Users View, click the user that you want to delete. This opens the Edit User dialog.

  1. Click the Delete button in the top right of the Edit User dialog.

  1. Click Delete again to confirm. The user is deleted.

Changing User Names

  1. In the Users View, click the user that you want to edit. This opens the Edit User dialog.

  2. In the Edit User dialog, enter a new user name in the Username field.

  3. To apply the changes, click Update. The dialog will close and the user name will be updated.

Adding Roles to Users

Roles provide a convenient way to assign multiple permissions at once. By adding roles to users, you can quickly grant them access to specific system functions without configuring individual permissions.

Assign roles based on job functions or responsibilities rather than individual users to maintain consistent access control across your organization.

  1. In the navigation panel, click User.

  2. In the Users View, click the user to whom you want to add roles. This opens the Edit User dialog.

  3. In the Edit User dialog, click the Roles field to open the list of available roles.

  1. Click the Roles field and select a role. You can repeat this step to assign multiple roles.

  2. Click Update. The dialog will close and the user will be updated with the selected roles.

Deleting Roles from Users

When a user's responsibilities change, you may need to remove roles from them to adjust their access permissions.

Removing a role removes all associated permissions from the user.

  1. In the navigation panel, click User.

  2. In the Users View, click the user from whom you want to remove roles. This opens the Edit User dialog.

  3. In the Edit User dialog, click the x next to the role name in the Roles field to remove the role.

  1. Click Update. The dialog will close and the user will be updated.

Assigning Individual Permissions to Users

While roles are the recommended way to manage permissions, there may be cases where you need to grant specific permissions to individual users without creating a new role.

  1. In the navigation panel, click User.

  2. In the Users View, click the user to whom you want to assign individual permissions. This opens the Edit User dialog.

  3. In the Edit User dialog, activate Advanced Mode.

  1. To assign individual permissions, click the + button to open the Add Permission dialog.

    • Select the permission type: HTTP for accessing the REST API using HTTP clients or MQTT for accessing MQTT topics on CybusMQ.

    • In the Endpoint field, enter the resource path, which follows MQTT topic conventions. The specified topic can be a single topic or a wildcard. HTTP permissions for the resource path follow an MQTT topic structure. This means that you can use wildcards (# and +) in valid expressions, and paths must start with a leading slash (/).

    • Select the access type: read, write, or both.

    • Click Add to add the permission.

  1. Click Update. The dialog will close and the user is updated with the new permissions.

Deleting Permissions from User

When specific permissions are no longer needed, you can remove them while keeping other permissions intact.

Removing individual permissions does not affect permissions granted through roles. To completely remove access to a resource, ensure the user doesn't have access through any assigned roles.

  1. In the navigation panel, click User.

  2. In the Users View, click the user to whom you want to assign individual permissions. This opens the Edit User dialog.

  3. In the Edit User dialog, activate Advanced Mode.

  1. To remove a permission, click its Remove button in the Action column of the permissions list.

  1. Click Update. The dialog will close and the user is updated.

Changing User Passwords

Regularly updating passwords is an important security practice.

  1. In the navigation panel, click User.

  2. In the Users View, click the user for whom you want to change the password. This opens the Edit User dialog.

  3. In the Edit User dialog, click Change Password.

  1. In the Password field, enter the new password and confirm it in the Confirm Password field.

  2. To apply the changes, click Update. The dialog will close and the user will be updated with changes.

To add users with pre-defined roles quickly, use the the .

To define roles and permissions more granularly, use the .

We recommend to manage permissions through roles rather than individual user permissions for easier maintenance. For more information, see .

default mode
advanced mode
Roles
Default Admin User
Activating the Advanced Mode of the Edit User dialog.
Activating the Advanced Mode of the Edit User dialog.