[ovirt-users] How to protect SHE VM from being deleted in following setup

Michal Skrivanek michal.skrivanek at redhat.com
Sun Feb 18 14:23:50 UTC 2018



> On 17 Feb 2018, at 08:22, Vrgotic, Marko <M.Vrgotic at activevideo.com> wrote:
> 
> Dear oVirt community,
>  
> I have SHE on the Gluster (not managed by SHE).
> Due to limitations of VM Portal, I have given couple of trusted Users, trimmed down Admin access, so that they can create VMs.
>  
> However, this does make me bit worried, since the SHE VM could get deleted as any other VM in the pool.

Why do you give them permissions to HE VM? You should be able to give them creation, but not let them delete VMs they do not own

>  
> The SHE VM has its own storage pool, but it’s part of same Hypervisor Cluster (limitations of available HW), therefore my Users can see it and accidentally delete it – it can happen!
>  
> QUESTION: Any advices that could help me protect SHE VM from being deleted?


There’s “Delete Protection” property for every VM, that prevents people from accidentally deleting them. Might be enough, messing with permissions might be tricky.

Thanks,
michal
>  
> Any suggestions, ideas are highly welcome.
>  
> Thank you.
>  
> Best regards,
> Marko Vrgotic
> _______________________________________________
> Users mailing list
> Users at ovirt.org <mailto:Users at ovirt.org>
> http://lists.ovirt.org/mailman/listinfo/users <http://lists.ovirt.org/mailman/listinfo/users>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ovirt.org/pipermail/users/attachments/20180218/cdebf9af/attachment.html>


More information about the Users mailing list