Group permissions at cluster level

--_000_86B3513E4A7B064599167816D519189698DF346320LAPPWGGCPMB04_ Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Hi, This could be a bug or a configuration issue, I'm not too sure yet. At the = moment if I apply group permissions using the PowerUserRole to the cluster = itself, then any VMs created in the user portal by users in that group don'= t get the UserVmManager role applied correctly. The user, authorization pro= vider and namespace fields are all blank meaning that VM is visible to all = users on the platform. If you do this with individual users' permissions though, it works as expec= ted and they get the UserVmManager role assigned to their username on the V= M. Thanks, Paul **************************************************************************** NHSGG&C Disclaimer The information contained within this e-mail and in any attachment is confidential and may be privileged. If you are not the intended recipient, please destroy this message, delete any copies held on your systems and notify the sender immediately; you should not retain, copy or use this e-mail for any purpose, nor disclose all or any part of its content to any other person. All messages passing through this gateway are checked for viruses, but we strongly recommend that you check for viruses using your own virus scanner as NHS Greater Glasgow & Clyde will not take responsibility for any damage caused as a result of virus infection. **************************************************************************= =20 --_000_86B3513E4A7B064599167816D519189698DF346320LAPPWGGCPMB04_ Content-Type: text/html; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content= =3D"text/html; charset=3Dus-ascii"><meta name=3DGenerator content=3D"Micros= oft Word 15 (filtered medium)"><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-fareast-language:EN-US;} a:link, span.MsoHyperlink {mso-style-priority:99; color:#0563C1; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:#954F72; text-decoration:underline;} span.EmailStyle17 {mso-style-type:personal-compose; font-family:"Calibri","sans-serif"; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-family:"Calibri","sans-serif"; mso-fareast-language:EN-US;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-GB link=3D"#0563C1= " vlink=3D"#954F72"><div class=3DWordSection1><p class=3DMsoNormal>Hi,<o:p>= </o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>Th= is could be a bug or a configuration issue, I’m not too sure yet. At = the moment if I apply group permissions using the PowerUserRole to the clus= ter itself, then any VMs created in the user portal by users in that group = don’t get the UserVmManager role applied correctly. The user, authori= zation provider and namespace fields are all blank meaning that VM is visib= le to all users on the platform.<o:p></o:p></p><p class=3DMsoNormal><o:p>&n= bsp;</o:p></p><p class=3DMsoNormal>If you do this with individual usersR= 17; permissions though, it works as expected and they get the UserVmManager= role assigned to their username on the VM.<o:p></o:p></p><p class=3DMsoNor= mal><o:p> </o:p></p><p class=3DMsoNormal>Thanks,<o:p></o:p></p><p clas= s=3DMsoNormal>Paul<o:p></o:p></p></div><p>*********************************= *******************************************<br> NHSGG&C Disclaimer</p> <p>The information contained within this e-mail and in any attachment is<br> confidential and may be privileged. If you are not the intended<br> recipient, please destroy this message, delete any copies held on your<br> systems and notify the sender immediately; you should not retain, copy<br> or use this e-mail for any purpose, nor disclose all or any part of its<br> content to any other person.</p> <p>All messages passing through this gateway are checked for viruses, but<b= r> we strongly recommend that you check for viruses using your own virus<br> scanner as NHS Greater Glasgow & Clyde will not take responsibility for= <br> any damage caused as a result of virus infection.</p> <p>************************************************************************= ** </p></body></html> --_000_86B3513E4A7B064599167816D519189698DF346320LAPPWGGCPMB04_--

On 10/26/2016 04:49 PM, Woodward, Paul wrote:
Hi,
This could be a bug or a configuration issue, I’m not too sure yet. At the moment if I apply group permissions using the PowerUserRole to the cluster itself, then any VMs created in the user portal by users in that group don’t get the UserVmManager role applied correctly. The user, authorization provider and namespace fields are all blank meaning that VM is visible to all users on the platform.
Thanks for the report. It's indeed a bug. Can you please report it in bugzilla here: https://bugzilla.redhat.com/enter_bug.cgi?product=ovirt-engine Thank you very much.
If you do this with individual users’ permissions though, it works as expected and they get the UserVmManager role assigned to their username on the VM.
Thanks,
Paul
**************************************************************************** NHSGG&C Disclaimer
The information contained within this e-mail and in any attachment is confidential and may be privileged. If you are not the intended recipient, please destroy this message, delete any copies held on your systems and notify the sender immediately; you should not retain, copy or use this e-mail for any purpose, nor disclose all or any part of its content to any other person.
All messages passing through this gateway are checked for viruses, but we strongly recommend that you check for viruses using your own virus scanner as NHS Greater Glasgow & Clyde will not take responsibility for any damage caused as a result of virus infection.
**************************************************************************
_______________________________________________ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
participants (2)
-
Ondra Machacek
-
Woodward, Paul