Ask Your Question

Is there a way of isolating tenant networks as all admins see all networks not just the ones that they created?

asked 2014-08-19 11:30:10 -0500

Gemma gravatar image

I am curious as to why all networks are visible to all admins even if they did not create the network. Is there a way of isolating tenant networks so you can only see the ones that you have created?

edit retag flag offensive close merge delete


what do you see as a User?

FredSmite gravatar imageFredSmite ( 2014-08-19 12:51:27 -0500 )edit

1 answer

Sort by ยป oldest newest most voted

answered 2014-08-21 10:38:26 -0500

mpetason gravatar image

It sounds like this is more of a configuration issue. You shouldn't have multiple administrators unless you are using Domains. You will only have one admin. Users that are the "administrator" of a tenant are not considered Admins, they are members, as members can do most actions unless the policies are modified.

Administrators should be able to see all tenant networks as they have the role of administering the environment. Admin != administrative user on a tenant, it is considered the admin of the environment.

Users should be setup as Member, or another specified user type if you modified policies to allow for splitting up permissions:

edit flag offensive delete link more


Thanks for that I will have a look at the configuration document.

Gemma gravatar imageGemma ( 2014-08-21 12:24:16 -0500 )edit

Well more so you'll want to assign most users to the Member category, which is done by default usually. Don't assign users that shouldn't have access to the entire cloud to the "admin" role.

mpetason gravatar imagempetason ( 2014-08-21 12:34:01 -0500 )edit

Get to know Ask OpenStack

Resources for moderators

Question Tools


Asked: 2014-08-19 11:30:10 -0500

Seen: 42 times

Last updated: Aug 21 '14