Is there a way to allow non-admin to create some sub-projects ?

asked 2015-04-21 09:55:58 -0600

TristanLT gravatar image

Hi, I use KeystoneV3 and Juno on Ubuntu 14.04. I wish allows all users to lists and creates projects into a defined root project. Root project is named "testzone".

I've try this couple of rules :

"inprojectzone": "'84a51db0fc4747b48e72fe45f35892e2':%(target.project.parents)s",
"identity:create_project": "rule:admin_required or rule:inprojectzone",

I've tried target.project.parents or target.project.parent_id without results...

Here is the code used to try to create projects

# ok
admclient.projects.create(domain="default", name="oui", description='My test projects', parent=parent)

Keystone answers

keystoneclient.openstack.common.apiclient.exceptions.Forbidden: You are not authorized to perform the requested action: identity:create_project

Is there a way to allows sub-projects creation to role or all into a defined project ?

Thank you, Tristanlt

edit retag flag offensive close merge delete

1 answer

Sort by ยป oldest newest most voted

answered 2015-04-21 18:45:13 -0600

With Keystone v3 you could use the Domains concept to isolate users from projects. You could have an admin user in Domain1 and they can create projects, users, etc. but they would not be able to do that in Domain2.

This Post provides more information and examples.

Also, the Identity API docs provide more information.

edit flag offensive delete link more


Thank you, this sound good for me. I've created domain "Projets" and I've added this rules :

   "in_projects_domain": "'b233cc6978fa45cfb9b4beb0698f93b0':%(target.project.domain_id)s",
    "identity:create_project": "rule:admin_required or rule:in_projects_domain",

Without results. I'm wrong?

TristanLT gravatar imageTristanLT ( 2015-04-26 07:59:20 -0600 )edit

Get to know Ask OpenStack

Resources for moderators

Question Tools



Asked: 2015-04-21 09:55:58 -0600

Seen: 535 times

Last updated: Apr 21 '15