[ovirt-users] Permissions
Hi Does anybody have any solution that I want give some user or group permissions to create vm and fully manage only vm what he creates. So users should not be able to see or make any changes on vm what are not created by him/groups where user belong, ___ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-le...@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/EDDC55P7DTPPFRQL6VACFUQEAIOW3V3G/
Re: [ovirt-users] Permissions to Import VMs
On Sat, May 20, 2017 at 12:15 AM, Peter Woodwrote: > I did create a bug report and it was closed with the explanation that > UserVmManager role is not assigned because I'm using the Administration > portal... (???). What other portal do I use? Import/Export is Admin type > operation. > > See here: > https://bugzilla.redhat.com/show_bug.cgi?id=1451501 > > > Very simple steps to test it: > > - Create a local user called LocalUserA > > - Grant permissions to create VMs in DEV1 cluster and Import/Export VMs: > > LocalUserA -> [PowerUserRole] -> DEV1 (Cluster) > LocalUserA -> [PowerUserRole] -> SAN (Storage Data Master) > LocalUserA -> [VmImporterExporter] -> DEV1 (Cluster) > LocalUserA -> [VmImporterExporter] -> SAN (Storage Data Master) > LocalUserA -> [VmImporterExporter] -> SD-Export (Storage Export type) > > - Login to the Administration Portal as LocalUserA@internal > > - Create a VM, Export the VM, Import the VM > > Role UserVmManager is not set for the imported VM. > User LocalUserA can not even boot up the VM due to insufficient > permissions. > > How do I setup LocalUserA so it can import VMs and work with them? > > Thanks for this information Peter. I proposed a patch. Let's discuss it in bugzilla. > Thank you, > > -- Peter > > > On Tue, May 16, 2017 at 4:11 AM, Arik Hadas wrote: > >> >> >> On Mon, May 15, 2017 at 11:36 PM, Peter Wood >> wrote: >> >>> Hi, >>> >>> I have a group of local users with permissions to create VMs, templates, >>> and VMs from templates. They are allowed to work only in one of the >>> clusters in the datacenter. >>> >>> Now I want one of the local users to be able to import VMs and convert >>> them into templates and I just can't find the recipe for that. >>> >>> The group has these permissions: >>> >>> LocalUsersGroup -> [PowerUserRole] -> DEV1 (Cluster) >>> LocalUsersGroup -> [PowerUserRole] -> SAN (Storage) >>> LocalUsersGroup -> [TemplateCreator] -> OFFICE (Datacenter) >>> >>> LocalUserA is part of LocalUsersGroup and should be able to: >>> - Import a VM >>> - Convert the VM to a template for everyone to use >>> - Delete the VM >>> >>> I tried this: LocalUserA -> [VmImporterExporter] -> System >>> >>> LocalUserA can now import VMs and convert them to templates but it can't >>> delete the imported VMs. For some reason [UserVmManager] role is not >>> assigned to LocalUserA on the VMs that were imported. >>> >> >> Right, that seems to be a bug. The import operation should set the user >> that executes it with UserVmManager role on the imported VM, just like add >> VM does for regular VM creation. >> Could you please file a bug? >> >> >>> >>> Before I start messing around I'd appreciate somebody's else opinion on >>> how this should be done. >>> >>> >> Thank you for your time, >>> >>> -- Peter >>> >>> >>> >>> ___ >>> Users mailing list >>> Users@ovirt.org >>> http://lists.ovirt.org/mailman/listinfo/users >>> >>> >> > ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [ovirt-users] Permissions to Import VMs
I did create a bug report and it was closed with the explanation that UserVmManager role is not assigned because I'm using the Administration portal... (???). What other portal do I use? Import/Export is Admin type operation. See here: https://bugzilla.redhat.com/show_bug.cgi?id=1451501 Very simple steps to test it: - Create a local user called LocalUserA - Grant permissions to create VMs in DEV1 cluster and Import/Export VMs: LocalUserA -> [PowerUserRole] -> DEV1 (Cluster) LocalUserA -> [PowerUserRole] -> SAN (Storage Data Master) LocalUserA -> [VmImporterExporter] -> DEV1 (Cluster) LocalUserA -> [VmImporterExporter] -> SAN (Storage Data Master) LocalUserA -> [VmImporterExporter] -> SD-Export (Storage Export type) - Login to the Administration Portal as LocalUserA@internal - Create a VM, Export the VM, Import the VM Role UserVmManager is not set for the imported VM. User LocalUserA can not even boot up the VM due to insufficient permissions. How do I setup LocalUserA so it can import VMs and work with them? Thank you, -- Peter On Tue, May 16, 2017 at 4:11 AM, Arik Hadaswrote: > > > On Mon, May 15, 2017 at 11:36 PM, Peter Wood > wrote: > >> Hi, >> >> I have a group of local users with permissions to create VMs, templates, >> and VMs from templates. They are allowed to work only in one of the >> clusters in the datacenter. >> >> Now I want one of the local users to be able to import VMs and convert >> them into templates and I just can't find the recipe for that. >> >> The group has these permissions: >> >> LocalUsersGroup -> [PowerUserRole] -> DEV1 (Cluster) >> LocalUsersGroup -> [PowerUserRole] -> SAN (Storage) >> LocalUsersGroup -> [TemplateCreator] -> OFFICE (Datacenter) >> >> LocalUserA is part of LocalUsersGroup and should be able to: >> - Import a VM >> - Convert the VM to a template for everyone to use >> - Delete the VM >> >> I tried this: LocalUserA -> [VmImporterExporter] -> System >> >> LocalUserA can now import VMs and convert them to templates but it can't >> delete the imported VMs. For some reason [UserVmManager] role is not >> assigned to LocalUserA on the VMs that were imported. >> > > Right, that seems to be a bug. The import operation should set the user > that executes it with UserVmManager role on the imported VM, just like add > VM does for regular VM creation. > Could you please file a bug? > > >> >> Before I start messing around I'd appreciate somebody's else opinion on >> how this should be done. >> >> > Thank you for your time, >> >> -- Peter >> >> >> >> ___ >> Users mailing list >> Users@ovirt.org >> http://lists.ovirt.org/mailman/listinfo/users >> >> > ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [ovirt-users] Permissions to Import VMs
On Mon, May 15, 2017 at 11:36 PM, Peter Woodwrote: > Hi, > > I have a group of local users with permissions to create VMs, templates, > and VMs from templates. They are allowed to work only in one of the > clusters in the datacenter. > > Now I want one of the local users to be able to import VMs and convert > them into templates and I just can't find the recipe for that. > > The group has these permissions: > > LocalUsersGroup -> [PowerUserRole] -> DEV1 (Cluster) > LocalUsersGroup -> [PowerUserRole] -> SAN (Storage) > LocalUsersGroup -> [TemplateCreator] -> OFFICE (Datacenter) > > LocalUserA is part of LocalUsersGroup and should be able to: > - Import a VM > - Convert the VM to a template for everyone to use > - Delete the VM > > I tried this: LocalUserA -> [VmImporterExporter] -> System > > LocalUserA can now import VMs and convert them to templates but it can't > delete the imported VMs. For some reason [UserVmManager] role is not > assigned to LocalUserA on the VMs that were imported. > Right, that seems to be a bug. The import operation should set the user that executes it with UserVmManager role on the imported VM, just like add VM does for regular VM creation. Could you please file a bug? > > Before I start messing around I'd appreciate somebody's else opinion on > how this should be done. > > Thank you for your time, > > -- Peter > > > > ___ > Users mailing list > Users@ovirt.org > http://lists.ovirt.org/mailman/listinfo/users > > ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
[ovirt-users] Permissions to Import VMs
Hi, I have a group of local users with permissions to create VMs, templates, and VMs from templates. They are allowed to work only in one of the clusters in the datacenter. Now I want one of the local users to be able to import VMs and convert them into templates and I just can't find the recipe for that. The group has these permissions: LocalUsersGroup -> [PowerUserRole] -> DEV1 (Cluster) LocalUsersGroup -> [PowerUserRole] -> SAN (Storage) LocalUsersGroup -> [TemplateCreator] -> OFFICE (Datacenter) LocalUserA is part of LocalUsersGroup and should be able to: - Import a VM - Convert the VM to a template for everyone to use - Delete the VM I tried this: LocalUserA -> [VmImporterExporter] -> System LocalUserA can now import VMs and convert them to templates but it can't delete the imported VMs. For some reason [UserVmManager] role is not assigned to LocalUserA on the VMs that were imported. Before I start messing around I'd appreciate somebody's else opinion on how this should be done. Thank you for your time, -- Peter ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
The bug is opened: https://bugzilla.redhat.com/show_bug.cgi?id=1071687 -Original Message- From: Itamar Heim [mailto:ih...@redhat.com] Sent: Sunday, March 02, 2014 4:25 PM To: Maurice James; 'Yair Zaslavsky' Cc: users@ovirt.org Subject: Re: [Users] Permissions On 02/26/2014 02:09 AM, Maurice James wrote: I tried removing the group and assigning Super User and Power user to the persona attempting the disk move and the result was the same. It only allows admin@internal to perform that function for some reason can you please open a bug for tracking. thanks -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Tuesday, February 25, 2014 6:59 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Yair Zaslavsky yzasl...@redhat.com Cc: Eli Mesika emes...@redhat.com, users@ovirt.org Sent: Wednesday, February 26, 2014 1:35:03 AM Subject: RE: [Users] Permissions Here are the logs that I grabbed while trying to move disks between storage domains It shows you have permissions issues. Just to make sure - is this a user that belongs to a group that has permissions? I think you wrote in previous emails it is. Can you, as suggested in previous email, try to perform this operation with a direct user that has the permissions (i.e - not inherited from a group?) Thanks, Yair -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Monday, February 24, 2014 8:56 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Eli Mesika emes...@redhat.com Cc: users@ovirt.org Sent: Tuesday, February 25, 2014 3:33:52 AM Subject: Re: [Users] Permissions I will have to get the logs to you tomorrow when I go to the office. Until then, I have a user group from AD with the Power User and Super User permissions over the Data Center. They do not have permission to move disks between storage domains. Is this by design? Maurice, quick question here - when you write they don't have permissions do you mean to users of the group? if so, are you using ovirt engine 3.4 beta2 or a development environment? Perhaps the following bug has to do with what you're experiencing? https://bugzilla.redhat.com/1065615 Yair -Original Message- From: Eli Mesika [mailto:emes...@redhat.com] Sent: Sunday, February 23, 2014 3:34 PM To: Maurice James Cc: users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
Here are the logs that I grabbed while trying to move disks between storage domains -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Monday, February 24, 2014 8:56 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Eli Mesika emes...@redhat.com Cc: users@ovirt.org Sent: Tuesday, February 25, 2014 3:33:52 AM Subject: Re: [Users] Permissions I will have to get the logs to you tomorrow when I go to the office. Until then, I have a user group from AD with the Power User and Super User permissions over the Data Center. They do not have permission to move disks between storage domains. Is this by design? Maurice, quick question here - when you write they don't have permissions do you mean to users of the group? if so, are you using ovirt engine 3.4 beta2 or a development environment? Perhaps the following bug has to do with what you're experiencing? https://bugzilla.redhat.com/1065615 Yair -Original Message- From: Eli Mesika [mailto:emes...@redhat.com] Sent: Sunday, February 23, 2014 3:34 PM To: Maurice James Cc: users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users oVorterre.log Description: Binary data ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
- Original Message - From: Maurice James midnightst...@msn.com To: Yair Zaslavsky yzasl...@redhat.com Cc: Eli Mesika emes...@redhat.com, users@ovirt.org Sent: Wednesday, February 26, 2014 1:35:03 AM Subject: RE: [Users] Permissions Here are the logs that I grabbed while trying to move disks between storage domains It shows you have permissions issues. Just to make sure - is this a user that belongs to a group that has permissions? I think you wrote in previous emails it is. Can you, as suggested in previous email, try to perform this operation with a direct user that has the permissions (i.e - not inherited from a group?) Thanks, Yair -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Monday, February 24, 2014 8:56 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Eli Mesika emes...@redhat.com Cc: users@ovirt.org Sent: Tuesday, February 25, 2014 3:33:52 AM Subject: Re: [Users] Permissions I will have to get the logs to you tomorrow when I go to the office. Until then, I have a user group from AD with the Power User and Super User permissions over the Data Center. They do not have permission to move disks between storage domains. Is this by design? Maurice, quick question here - when you write they don't have permissions do you mean to users of the group? if so, are you using ovirt engine 3.4 beta2 or a development environment? Perhaps the following bug has to do with what you're experiencing? https://bugzilla.redhat.com/1065615 Yair -Original Message- From: Eli Mesika [mailto:emes...@redhat.com] Sent: Sunday, February 23, 2014 3:34 PM To: Maurice James Cc: users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
I tried removing the group and assigning Super User and Power user to the persona attempting the disk move and the result was the same. It only allows admin@internal to perform that function for some reason -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Tuesday, February 25, 2014 6:59 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Yair Zaslavsky yzasl...@redhat.com Cc: Eli Mesika emes...@redhat.com, users@ovirt.org Sent: Wednesday, February 26, 2014 1:35:03 AM Subject: RE: [Users] Permissions Here are the logs that I grabbed while trying to move disks between storage domains It shows you have permissions issues. Just to make sure - is this a user that belongs to a group that has permissions? I think you wrote in previous emails it is. Can you, as suggested in previous email, try to perform this operation with a direct user that has the permissions (i.e - not inherited from a group?) Thanks, Yair -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Monday, February 24, 2014 8:56 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Eli Mesika emes...@redhat.com Cc: users@ovirt.org Sent: Tuesday, February 25, 2014 3:33:52 AM Subject: Re: [Users] Permissions I will have to get the logs to you tomorrow when I go to the office. Until then, I have a user group from AD with the Power User and Super User permissions over the Data Center. They do not have permission to move disks between storage domains. Is this by design? Maurice, quick question here - when you write they don't have permissions do you mean to users of the group? if so, are you using ovirt engine 3.4 beta2 or a development environment? Perhaps the following bug has to do with what you're experiencing? https://bugzilla.redhat.com/1065615 Yair -Original Message- From: Eli Mesika [mailto:emes...@redhat.com] Sent: Sunday, February 23, 2014 3:34 PM To: Maurice James Cc: users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
- Original Message - From: Maurice James midnightst...@msn.com To: Eli Mesika emes...@redhat.com Cc: users@ovirt.org Sent: Tuesday, February 25, 2014 3:33:52 AM Subject: Re: [Users] Permissions I will have to get the logs to you tomorrow when I go to the office. Until then, I have a user group from AD with the Power User and Super User permissions over the Data Center. They do not have permission to move disks between storage domains. Is this by design? Maurice, quick question here - when you write they don't have permissions do you mean to users of the group? if so, are you using ovirt engine 3.4 beta2 or a development environment? Perhaps the following bug has to do with what you're experiencing? https://bugzilla.redhat.com/1065615 Yair -Original Message- From: Eli Mesika [mailto:emes...@redhat.com] Sent: Sunday, February 23, 2014 3:34 PM To: Maurice James Cc: users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
I will give that a try. I will add the user directly instead of the group to see if that makes a difference. To answer your question, yes I added the group that the users belong to. They can do other things like, create VMs and storage. The only thing that Ive found that they couldn’t do so far is migrate disks. For this set up im using oVirt Engine Version: 3.3.3-2.el6 -Original Message- From: Yair Zaslavsky [mailto:yzasl...@redhat.com] Sent: Monday, February 24, 2014 8:56 PM To: Maurice James Cc: Eli Mesika; users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: Eli Mesika emes...@redhat.com Cc: users@ovirt.org Sent: Tuesday, February 25, 2014 3:33:52 AM Subject: Re: [Users] Permissions I will have to get the logs to you tomorrow when I go to the office. Until then, I have a user group from AD with the Power User and Super User permissions over the Data Center. They do not have permission to move disks between storage domains. Is this by design? Maurice, quick question here - when you write they don't have permissions do you mean to users of the group? if so, are you using ovirt engine 3.4 beta2 or a development environment? Perhaps the following bug has to do with what you're experiencing? https://bugzilla.redhat.com/1065615 Yair -Original Message- From: Eli Mesika [mailto:emes...@redhat.com] Sent: Sunday, February 23, 2014 3:34 PM To: Maurice James Cc: users@ovirt.org Subject: Re: [Users] Permissions - Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
Re: [Users] Permissions
- Original Message - From: Maurice James midnightst...@msn.com To: users@ovirt.org Sent: Friday, February 21, 2014 9:25:12 PM Subject: [Users] Permissions I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? Hi Maurice Can you elaborate please and attach a screen-shot of the error you got and the relevant engine.log oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
[Users] Permissions
I have an LDAP user with Power User and Super User permissions at the Data Center level. Why dont I have permission to migrate disks between storage domains? oVirt Engine Version: 3.3.3-2.el6 ___ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users