第 4 章 管理组
您可以使用 Identity Service (keystone)组为多个用户帐户分配一致的权限。
4.1. 使用 CLI 配置组 复制链接链接已复制到粘贴板!
复制链接链接已复制到粘贴板!
创建组并为组分配权限。组成员会继承您分配给组的相同权限:
创建组
grp-Auditors:Copy to Clipboard Copied! Toggle word wrap Toggle overflow 查看 keystone 组列表:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 授予
grp-Auditors组权限来访问demo项目,同时使用member角色:openstack role add member --group grp-Auditors --project demo
$ openstack role add member --group grp-Auditors --project demoCopy to Clipboard Copied! Toggle word wrap Toggle overflow 将现有用户
user1添加到grp-Auditors组中:openstack group add user grp-Auditors user1
$ openstack group add user grp-Auditors user1 user1 added to group grp-AuditorsCopy to Clipboard Copied! Toggle word wrap Toggle overflow 确认
user1是grp-Auditors的成员:openstack group contains user grp-Auditors user1
$ openstack group contains user grp-Auditors user1 user1 in group grp-AuditorsCopy to Clipboard Copied! Toggle word wrap Toggle overflow 查看分配给
user1的有效权限:Copy to Clipboard Copied! Toggle word wrap Toggle overflow