Roles and permissions


Related topics

Planning

The following lists the user roles for BMC AMI DevOps for Db2 and describes their associated permissions:

RoleDescription
System programmer

As the system programmer, you install and maintain the operating system and installs, upgrades, and maintains products that run on the system.   

To install BMC AMI DevOps for Db2, your user ID must have the following permissions, privileges, and authorizations:

  • Add, edit, and delete external security manager (ESM) user profiles (in collaboration with the security administrator)
  • Read, write, and execute in z/OS UNIX System Services (USS)
  • Create, edit, and delete z/OS File System (zFS) directories
  • Add the product’s load library to an APF-authorized library
  • Configure and validate TCP/IP connectivity for RESTful API calls
  • Transfer installation files (binary TSO XMIT format) via FTP or IND$FILE from your workstation to the target z/OS system
Security administrator    

As the security administrator, you work with the system programmer to plan and implement ESM user IDs, initial passwords, and password policies.

You also perform the following tasks:

  • Creating and managing RACF/ACF2/Top Secret profiles for product access
  • Defining SAF resource classes for DevOps job execution
  • Setting up group roles and permissions for continuous integration/continuous delivery (CI/CD) integration
  • Ensuring compliance with enterprise security standards
DevOps engineer    

As the DevOps engineer, you configure the product after installation and integrate it into CI/CD pipelines.

You also perform the following tasks:

  • Installing or pushing and pulling CI/CD artifacts for the BMC AMI DevOps hpi or image
  • Creating and managing YAML configuration files for schema deployment
Application developer

As the application developer, you configure the product after installation and integrate it into CI/CD pipelines.

You also perform the following tasks:

  • Updating the CI/CD tool with inputs for the developer's schema definitions for schema deployment
  • Submitting jobs via Jenkins, Azure DevOps, GitHub Actions, or GitLab CI/CD
  • Reviewing impact analysis reports and Schema Standards rule violations
  • Collaborating with Db2 DBAs to validate and approve schema changes
Db2 DBA

As the Db2 DBA, you support the product by maintaining the Db2 subsystem and application schema by using Db2 catalog, Db2 subsystem control commands, and Buffer pool and log management.

 

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC AMI DevOps for Db2 13.1