
I have a user that I want to be able to create VMs, create and attach disks to the new VM, add a network interface to the VM, and get the OS installed so it is ready to use. I am completely confused on which role (or roles) this user would need to do that without making them an admin. Can someone give me some guidance here? -- Kristian Petersen System Administrator BYU Dept. of Chemistry and Biochemistry

--_000_b33246531f0f4084bd0391e4e0efe936KBNMXEXC01Demantcom_ Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 SGkgS3Jpc3RpYW4sDQoNCkFzIGZhciBhcyBJ4oCZdmUgZXhwZXJpZW5jZWQgbXlzZWxmLCB0b28s IHRoZXkgd291bGQgbmVlZCBvbmUgb3IgbW9yZSBhZG1pbiByb2xlcy9wZXJtaXNzaW9ucy4gVGhl IHBlcm1pc3Npb25zIGNhbiBob3dldmVyIGJlIHF1aXRlIGZyZWVseSBkaXN0cmlidXRlZCB0byB0 aGUgdXNlciwgYW5kIHNpbmNlIHlvdSBjYW4gY3JlYXRlIGEgY3VzdG9tIHJvbGUsIHRvbywgaXQg c2hvdWxkIGJlIHBvc3NpYmxlIHRvIHN0aXRjaCB0b2dldGhlciBhIHJhdGhlciBsaW1pdGVkIGFk bWluLXJvbGUuDQpSZWd1bGFyIG5vbi1hZG1pbiBwcml2aWxlZ2VzIHN1cHBvc2VkbHkgb25seSBn aXZlcyBhY2Nlc3MgdG8gdGhlIFZNIFBvcnRhbCBhbmQgbm90IGFjdHVhbGx5IHRoZSBBZG1pbmlz dHJhdGlvbiBQb3J0YWwgKGluIHdoaWNoIHlvdSBjb3VsZCBkbyBhbGwgb2YgdGhpcykuDQoNCg0K QWxsIHRoZSBiZXN0LA0KTWlrZQ0KDQoNCkZyb206IHVzZXJzLWJvdW5jZXNAb3ZpcnQub3JnIFtt YWlsdG86dXNlcnMtYm91bmNlc0BvdmlydC5vcmddIE9uIEJlaGFsZiBPZiBLcmlzdGlhbiBQZXRl cnNlbg0KU2VudDogMS4gbWFqIDIwMTggMTc6MzYNClRvOiB1c2VycyA8dXNlcnNAb3ZpcnQub3Jn Pg0KU3ViamVjdDogW292aXJ0LXVzZXJzXSBVc2VyIHBvcnRhbCBwZXJtaXNzaW9ucw0KDQpJIGhh dmUgYSB1c2VyIHRoYXQgSSB3YW50IHRvIGJlIGFibGUgdG8gY3JlYXRlIFZNcywgY3JlYXRlIGFu ZCBhdHRhY2ggZGlza3MgdG8gdGhlIG5ldyBWTSwgYWRkIGEgbmV0d29yayBpbnRlcmZhY2UgdG8g dGhlIFZNLCBhbmQgZ2V0IHRoZSBPUyBpbnN0YWxsZWQgc28gaXQgaXMgcmVhZHkgdG8gdXNlLiAg SSBhbSBjb21wbGV0ZWx5IGNvbmZ1c2VkIG9uIHdoaWNoIHJvbGUgKG9yIHJvbGVzKSB0aGlzIHVz ZXIgd291bGQgbmVlZCB0byBkbyB0aGF0IHdpdGhvdXQgbWFraW5nIHRoZW0gYW4gYWRtaW4uICBD YW4gc29tZW9uZSBnaXZlIG1lIHNvbWUgZ3VpZGFuY2UgaGVyZT8NCg0KLS0NCktyaXN0aWFuIFBl dGVyc2VuDQpTeXN0ZW0gQWRtaW5pc3RyYXRvcg0KQllVIERlcHQuIG9mIENoZW1pc3RyeSBhbmQg QmlvY2hlbWlzdHJ5DQo= --_000_b33246531f0f4084bd0391e4e0efe936KBNMXEXC01Demantcom_ Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: base64 PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6 IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1m YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy IDQ7fQ0KLyogU3R5bGUgRGVmaW5pdGlvbnMgKi8NCnAuTXNvTm9ybWFsLCBsaS5Nc29Ob3JtYWws IGRpdi5Nc29Ob3JtYWwNCgl7bWFyZ2luOjBjbTsNCgltYXJnaW4tYm90dG9tOi4wMDAxcHQ7DQoJ Zm9udC1zaXplOjExLjBwdDsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9DQph OmxpbmssIHNwYW4uTXNvSHlwZXJsaW5rDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xv cjojMDU2M0MxOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KYTp2aXNpdGVkLCBzcGFu Lk1zb0h5cGVybGlua0ZvbGxvd2VkDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjoj OTU0RjcyOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KcC5tc29ub3JtYWwwLCBsaS5t c29ub3JtYWwwLCBkaXYubXNvbm9ybWFsMA0KCXttc28tc3R5bGUtbmFtZTptc29ub3JtYWw7DQoJ bXNvLW1hcmdpbi10b3AtYWx0OmF1dG87DQoJbWFyZ2luLXJpZ2h0OjBjbTsNCgltc28tbWFyZ2lu LWJvdHRvbS1hbHQ6YXV0bzsNCgltYXJnaW4tbGVmdDowY207DQoJZm9udC1zaXplOjExLjBwdDsN Cglmb250LWZhbWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9DQpzcGFuLkVtYWlsU3R5bGUxOA0K CXttc28tc3R5bGUtdHlwZTpwZXJzb25hbC1yZXBseTsNCglmb250LWZhbWlseToiQ2FsaWJyaSIs c2Fucy1zZXJpZjsNCgljb2xvcjp3aW5kb3d0ZXh0O30NCi5Nc29DaHBEZWZhdWx0DQoJe21zby1z dHlsZS10eXBlOmV4cG9ydC1vbmx5Ow0KCWZvbnQtZmFtaWx5OiJDYWxpYnJpIixzYW5zLXNlcmlm Ow0KCW1zby1mYXJlYXN0LWxhbmd1YWdlOkVOLVVTO30NCkBwYWdlIFdvcmRTZWN0aW9uMQ0KCXtz aXplOjYxMi4wcHQgNzkyLjBwdDsNCgltYXJnaW46My4wY20gMi4wY20gMy4wY20gMi4wY207fQ0K ZGl2LldvcmRTZWN0aW9uMQ0KCXtwYWdlOldvcmRTZWN0aW9uMTt9DQotLT48L3N0eWxlPjwhLS1b aWYgZ3RlIG1zbyA5XT48eG1sPg0KPG86c2hhcGVkZWZhdWx0cyB2OmV4dD0iZWRpdCIgc3BpZG1h eD0iMTAyNiIgLz4NCjwveG1sPjwhW2VuZGlmXS0tPjwhLS1baWYgZ3RlIG1zbyA5XT48eG1sPg0K PG86c2hhcGVsYXlvdXQgdjpleHQ9ImVkaXQiPg0KPG86aWRtYXAgdjpleHQ9ImVkaXQiIGRhdGE9 IjEiIC8+DQo8L286c2hhcGVsYXlvdXQ+PC94bWw+PCFbZW5kaWZdLS0+DQo8L2hlYWQ+DQo8Ym9k eSBsYW5nPSJEQSIgbGluaz0iIzA1NjNDMSIgdmxpbms9IiM5NTRGNzIiPg0KPGRpdiBjbGFzcz0i V29yZFNlY3Rpb24xIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJtc28tZmFy ZWFzdC1sYW5ndWFnZTpFTi1VUyI+SGkgS3Jpc3RpYW4sPG86cD48L286cD48L3NwYW4+PC9wPg0K PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9Im1zby1mYXJlYXN0LWxhbmd1YWdlOkVO LVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48 c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9Im1zby1mYXJlYXN0LWxhbmd1YWdlOkVOLVVTIj5BcyBm YXIgYXMgSeKAmXZlIGV4cGVyaWVuY2VkIG15c2VsZiwgdG9vLCB0aGV5IHdvdWxkIG5lZWQgb25l IG9yIG1vcmUgYWRtaW4gcm9sZXMvcGVybWlzc2lvbnMuIFRoZSBwZXJtaXNzaW9ucyBjYW4gaG93 ZXZlciBiZSBxdWl0ZSBmcmVlbHkgZGlzdHJpYnV0ZWQgdG8gdGhlIHVzZXIsIGFuZCBzaW5jZSB5 b3UgY2FuIGNyZWF0ZQ0KIGEgY3VzdG9tIHJvbGUsIHRvbywgaXQgc2hvdWxkIGJlIHBvc3NpYmxl IHRvIHN0aXRjaCB0b2dldGhlciBhIHJhdGhlciBsaW1pdGVkIGFkbWluLXJvbGUuPG86cD48L286 cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0 eWxlPSJtc28tZmFyZWFzdC1sYW5ndWFnZTpFTi1VUyI+UmVndWxhciBub24tYWRtaW4gcHJpdmls ZWdlcyBzdXBwb3NlZGx5IG9ubHkgZ2l2ZXMgYWNjZXNzIHRvIHRoZSBWTSBQb3J0YWwgYW5kIG5v dCBhY3R1YWxseSB0aGUgQWRtaW5pc3RyYXRpb24gUG9ydGFsIChpbiB3aGljaCB5b3UgY291bGQg ZG8gYWxsIG9mIHRoaXMpLjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0ibXNvLWZhcmVhc3QtbGFuZ3VhZ2U6RU4tVVMi PjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFu IGxhbmc9IkVOLVVTIiBzdHlsZT0ibXNvLWZhcmVhc3QtbGFuZ3VhZ2U6RU4tVVMiPjxvOnA+Jm5i c3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVO LVVTIiBzdHlsZT0ibXNvLWZhcmVhc3QtbGFuZ3VhZ2U6RU4tVVMiPkFsbCB0aGUgYmVzdCw8bzpw PjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1V UyIgc3R5bGU9Im1zby1mYXJlYXN0LWxhbmd1YWdlOkVOLVVTIj5NaWtlPG86cD48L286cD48L3Nw YW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJt c28tZmFyZWFzdC1sYW5ndWFnZTpFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0K PHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJtc28tZmFyZWFz dC1sYW5ndWFnZTpFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9 Ik1zb05vcm1hbCI+PGI+PHNwYW4gbGFuZz0iRU4tVVMiPkZyb206PC9zcGFuPjwvYj48c3BhbiBs YW5nPSJFTi1VUyI+IHVzZXJzLWJvdW5jZXNAb3ZpcnQub3JnIFttYWlsdG86dXNlcnMtYm91bmNl c0BvdmlydC5vcmddDQo8Yj5PbiBCZWhhbGYgT2YgPC9iPktyaXN0aWFuIFBldGVyc2VuPGJyPg0K PGI+U2VudDo8L2I+IDEuIG1haiAyMDE4IDE3OjM2PGJyPg0KPGI+VG86PC9iPiB1c2VycyAmbHQ7 dXNlcnNAb3ZpcnQub3JnJmd0Ozxicj4NCjxiPlN1YmplY3Q6PC9iPiBbb3ZpcnQtdXNlcnNdIFVz ZXIgcG9ydGFsIHBlcm1pc3Npb25zPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1z b05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h bCI+SSBoYXZlIGEgdXNlciB0aGF0IEkgd2FudCB0byBiZSBhYmxlIHRvIGNyZWF0ZSBWTXMsIGNy ZWF0ZSBhbmQgYXR0YWNoIGRpc2tzIHRvIHRoZSBuZXcgVk0sIGFkZCBhIG5ldHdvcmsgaW50ZXJm YWNlIHRvIHRoZSBWTSwgYW5kIGdldCB0aGUgT1MgaW5zdGFsbGVkIHNvIGl0IGlzIHJlYWR5IHRv IHVzZS4mbmJzcDsgSSBhbSBjb21wbGV0ZWx5IGNvbmZ1c2VkIG9uIHdoaWNoIHJvbGUgKG9yIHJv bGVzKSB0aGlzIHVzZXIgd291bGQNCiBuZWVkIHRvIGRvIHRoYXQgd2l0aG91dCBtYWtpbmcgdGhl bSBhbiBhZG1pbi4mbmJzcDsgQ2FuIHNvbWVvbmUgZ2l2ZSBtZSBzb21lIGd1aWRhbmNlIGhlcmU/ PGJyIGNsZWFyPSJhbGwiPg0KPG86cD48L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05v cm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi Pi0tIDxvOnA+PC9vOnA+PC9wPg0KPGRpdj4NCjxkaXY+DQo8ZGl2Pg0KPGRpdj4NCjxkaXY+DQo8 ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+S3Jpc3RpYW4gUGV0ZXJzZW48bzpwPjwvbzpwPjwv cD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5TeXN0ZW0gQWRtaW5pc3RyYXRvcjxvOnA+ PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+QllVIERlcHQu IG9mIENoZW1pc3RyeSBhbmQgQmlvY2hlbWlzdHJ5PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjwv ZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9k aXY+DQo8L2JvZHk+DQo8L2h0bWw+DQo= --_000_b33246531f0f4084bd0391e4e0efe936KBNMXEXC01Demantcom_--

--_000_152525349479624588leedsbeckettacuk_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello Kristian, I haven't upgraded to 4.2 yet but in 4.1 I create a Directory services group and add the user to it Then I give the user roles VmCreator DiskProfileUser VnicProfileUser These can be added to a DC, storage domain, cluster, etc. The VnicProfileUser means that you can restrict networks and impose QOS, N= etwork Filters,etc. We then add UserTemplateBasedVm permission to give them access to specific = templates. For users we allow to create templates we add TemplateCreator permission to= their group. These are all user permissions so they can't login to the admin portal. Regards, Paul S. ________________________________ From: users-bounces@ovirt.org <users-bounces@ovirt.org> on behalf of Kristi= an Petersen <nesretep@chem.byu.edu> Sent: 01 May 2018 16:36 To: users Subject: [ovirt-users] User portal permissions I have a user that I want to be able to create VMs, create and attach disks= to the new VM, add a network interface to the VM, and get the OS installed= so it is ready to use. I am completely confused on which role (or roles) = this user would need to do that without making them an admin. Can someone = give me some guidance here? -- Kristian Petersen System Administrator BYU Dept. of Chemistry and Biochemistry To view the terms under which this email is distributed, please go to:- http://disclaimer.leedsbeckett.ac.uk/disclaimer/disclaimer.html --_000_152525349479624588leedsbeckettacuk_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-= 1"> <style type=3D"text/css" style=3D"display:none"><!--P{margin-top:0;margin-b= ottom:0;} --></style> </head> <body dir=3D"ltr" style=3D"font-size:12pt;color:#000000;background-color:#F= FFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;"> <p>Hello Kristian,</p> <p><br> </p> <p>I haven't upgraded to 4.2 yet but in 4.1 </p> <p><br> </p> <p>I create a Directory services group and add the user to it</p> <p>Then I give the user roles </p> <p><br> </p> <p>VmCreator = <br> </p> <p>DiskProfileUser</p> <p>VnicProfileUser </p> <p><br> </p> <p>These can be added to a DC, storage domain, cluster, etc.</p> <p><br> </p> <p>The VnicProfileUser means that you can restric= t networks and impose QOS, Network Filters,etc.</p> <p><br> </p> <p>We then add UserTemplateBasedVm permission to give them access= to specific templates.</p> <p><br> </p> <p>For users we allow to create templates we add&n= bsp;TemplateCreator permission to their group.</p> <p><br> </p> <p>These are all user permissions so they can't lo= gin to the admin portal.</p> <p><br> </p> <p>Regards,</p> <p> = Paul S. <br> </p> <p><br> </p> <p><br> </p> <p><br> </p> <div style=3D"color: rgb(33, 33, 33);"> <hr tabindex=3D"-1" style=3D"display:inline-block; width:98%"> <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font style=3D"font-size:11pt" face= =3D"Calibri, sans-serif" color=3D"#000000"><b>From:</b> users-bounces@ovirt= .org <users-bounces@ovirt.org> on behalf of Kristian Petersen <nes= retep@chem.byu.edu><br> <b>Sent:</b> 01 May 2018 16:36<br> <b>To:</b> users<br> <b>Subject:</b> [ovirt-users] User portal permissions</font> <div> </div> </div> <div> <div dir=3D"ltr">I have a user that I want to be able to create VMs, create= and attach disks to the new VM, add a network interface to the VM, and get= the OS installed so it is ready to use. I am completely confused on = which role (or roles) this user would need to do that without making them an admin. Can someone give me some gu= idance here?<br clear=3D"all"> <div><br> </div> -- <br> <div class=3D"gmail_signature"> <div dir=3D"ltr"> <div> <div dir=3D"ltr"> <div> <div dir=3D"ltr">Kristian Petersen <div>System Administrator</div> <div>BYU Dept. of Chemistry and Biochemistry</div> </div> </div> </div> </div> </div> </div> </div> </div> </div> To view the terms under which this email is distributed, please go to:- <br=
<a href=3D"http://disclaimer.leedsbeckett.ac.uk/disclaimer/disclaimer.html"= target=3D"_blank">http://disclaimer.leedsbeckett.ac.uk/disclaimer/disclaim= er.html</a> <p></p> </body> </html> --_000_152525349479624588leedsbeckettacuk_--
participants (3)
-
Kristian Petersen
-
Michael Mortensen (MCMR)
-
Staniforth, Paul