Hi Ricardo,

If a domain admin creates a load balancer on an isolated network which
belongs to another account, domainid/account should be passed.
By the way, did you do it by API or UI ?

-Wei

On Wed, 27 Jul 2022 at 16:20, Ricardo Pertuz <ricardo.per...@kuasar.co>
wrote:

> Thanks Wei for replying, the caller has the role Domain Admin, so we guess
> it should be able to execute it
>
> On 27/07/22, 9:15 AM, "Wei ZHOU" <ustcweiz...@gmail.com> wrote:
>
>     Hi Ricardo,
>
>     Please check if the caller is the owner of the network, or the caller
> can
>     access the network if it belongs to a project.
>
>     -Wei
>
>     On Tue, 26 Jul 2022 at 23:16, Ricardo Pertuz <ricardo.per...@kuasar.co
> >
>     wrote:
>
>     > Hi all,
>     >
>     > We use a domain controller  user in ACS  to deploy the
> infrastructure,
>     > however when we try to CreateLoadBalancer we are receiving a “531
> Unable to
>     > use network with id= 498611f9-xxx-4030-aa10-e7d7ad062d1a, permission
> denied”
>     >
>     > PermissionDenied: Unable to use network with id=
>     > 498611f9-xxx-4030-aa10-e7d7ad062d1a, permission denied on objs: []
>     >
>     > Is there any configuration missing or is it a bug? It works well when
>     > using the admin user.
>     >
>     > ACS 4.15.2.0
>     > KVM
>     > Redundant VPC offering
>     >
>     > Supported Services on Network Offering
>     > SourceNat : VpcVirtualRouter
>     > Dhcp : VpcVirtualRouter
>     > Lb : InternalLbVm
>     > UserData : VpcVirtualRouter
>     > Dns : VpcVirtualRouter
>     > NetworkACL : VpcVirtualRouter
>     >
>     > BR,
>     >
>     > Ricardo
>     >
>     >
>     >
>     >
>
>

Reply via email to