Is it possible to have separate floating-IP pools and grant a tenant access to only some of them? Thought popped into my head while looking at the rbac-network spec here: https://review.openstack.org/#/c/132661/4/specs/liberty/rbac-networks.rst Creating individual pools, allowing only some tenants access and having off-cloud network ACLs would get part way to satisfying the use cases that drive the above spec (I'm thinking of this as a more short term solution, certainly not a direct alternative). I'm sure this is answered elsewhere but I couldn't find any direct information so I'm assuming no, it isn't supported but I wonder how much effort would be required to make it work? -Rob -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20150918/647df468/attachment.html>