How to Debug Authorisation Errors in Platform Manager

This guide shows you how to get Platform Manager to log the access decision behind an unexpected authorisation error, and how to read what it produces.

Type

How-to guide

Goal

See which access check Platform Manager failed, and on what grounds.

Audience

Platform Operator who can edit Platform Manager’s configuration and apply it.

When to use

Use this guide when a user is refused an action in Self-Service that their role should permit, or granted one it should not.

Prerequisites

Confirm the following before you begin.

Access and permissions required

You need the following access and permissions:

  • Permission to edit Platform Manager’s application.yml and apply it.

  • Read access to Platform Manager’s pod logs.

Tools and versions required

You need the following tools:

  • kubectl >= 1.28, for reading the resulting logs.

Resources that must exist before starting

The following must already exist:

  • A reproducible case. The logging below records decisions as they happen, so you need to be able to trigger the error again once it is on.

Enable access decision logging

Platform Manager authorises through Spring Security, which logs each access decision at DEBUG. That logger is off by default because it is noisy.

Add the following to Platform Manager’s application.yml:

logging:
  level:
    org.springframework.security.access: DEBUG

This sets one package rather than the whole service, so the rest of Platform Manager keeps logging at its normal level. Raise the level for one package only covers doing the same thing through the chart’s logging block.

Read the output and turn it off

Reproduce the error, then read the logs. Each denied request produces the authority the check required and the authorities the caller presented, which is normally enough to tell a missing group membership from a misconfigured role.

Replace every <VALUE> placeholder with your own value before running a command.
kubectl logs <PLATFORM_MANAGER_POD> --namespace axual | grep 'org.springframework.security.access'

The governance charts install into axual by convention, so substitute your own namespace when Platform Manager runs elsewhere.

Remove the logging change once you have the answer and the check in the next section passes. Left on, it logs a decision for every authorised request on the platform, which fills the log stream and costs money in a metered central stack.

Confirm the error is gone

The symptom this guide starts from is a user refused an action in Self-Service that their role should permit, or granted one it should not. Correct the group membership or role assignment the log output pointed at, then have that same user repeat that same action while the logging is still on.

  1. Sign in to Self-Service as the affected user.

  2. Repeat the action that produced the error.

  3. Read the logs again for the retried request.

    kubectl logs <PLATFORM_MANAGER_POD> --namespace axual | grep 'org.springframework.security.access'

A refusal that is now fixed completes in the interface without an error, and the retried request adds no denial to the log. An action that was wrongly permitted is now refused instead, and the log records that denial. Where the same denial appears again naming the same required authority, the change has not reached this user, so check the assignment against Roles & Permissions before changing anything else.