Dear OpenStack Community,
I hope this message finds you well.
I am reaching out to seek clarification and guidance on a scenario involving custom roles and sub-user management within OpenStack.
In our deployment, we have the standard admin
role as well as a custom role called super_user
, which grants privileges for CRUD operations on projects, role assignments, and user management. We currently have two users with the super_user
role, named Alice and John.
Each of these super_user
accounts manages their own sub-users: Alice manages the ABC
sub-users, and John manages the XYZ
sub-users.
I would like to implement a restriction where Alice, as a super_user
, can only manage the A,B,C
sub-users and should not be able to delete or manage John's X,Y,Z
sub-users. Similarly, John should not be able to manage or delete Alice's A,B,C
sub-users.
My questions are as follows:
ABC
sub-users belong to Alice and X,Y,Z
sub-users belong to John?Any insights, best practices, or suggestions on how to configure this within OpenStack would be greatly appreciated.
Thank you for your assistance and support.
Thamanna Farhath | Associate Engineer-R&DPh No: (+91) 9344093591
email: thamanna.f@zybisys.comZybisys Consulting LLP | NO.1B 2nd floor, NSA Tower,Akila Nagar, Main Rd, Ganapathy Nagar, Thiruvanaikoil, Tiruchirappalli, Tamil Nadu 620005zybisys.com