You are not authorized to perform the requested action under admin user

asked 2019-09-05 22:53:31 -0600

corey gravatar image

I have two accounts on OpenStack (admin and corey), I would like to raise the permission of "corey" up to admin, and this is what I have done.

$ openstack role add --project service --user corey admin

$ source

Nothing changed. So I tried this.

$ openstack role set --name corey admin

After doing this, both admin and corey lost all permissions, all commands can't work correctly.

$ openstack role list

You are not authorized to perform the requested action: identity:list_roles. (HTTP 403)

$ nova list

ERROR (ClientException): The server is currently unavailable. Please try again at a later time. (HTTP 503)

I can't see any info. on Horizon either, I logged in as admin, all I got is:

Error: Unable to retrieve instances

What should I do to fix this problem, I have completely no idea now.

edit retag flag offensive close merge delete

1 answer

Sort by ยป oldest newest most voted

answered 2019-09-06 00:19:34 -0600

With openstack role set --name corey admin, you renamed the admin role corey. As a result, this role is not the admin role anymore.

Before that, you gave corey the admin role in project service. My guess is that does not set the project to service. Thus, no admin privileges for corey.

How to fix this? Either by changing the name of the former admin role back to admin directly in the database. Or by using the ADMIN_TOKENto temporarily work around the lack of an admin role. To use the admin token, see

edit flag offensive delete link more


I went into the database and changed the name of the former admin role back to admin, it works! Thanks!

corey gravatar imagecorey ( 2019-09-06 02:01:34 -0600 )edit

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower


Asked: 2019-09-05 22:53:31 -0600

Seen: 1,284 times

Last updated: Sep 06 '19