...
Excerpt |
---|
Note |
---|
title | Changes to scopes from Abiquo 4.0 |
---|
| - Now administrators assign scopes to Abiquo users. In previous versions, administrators assigned scopes to Abiquo roles and the global scope was the default
- During the upgrade process to version 4.0, Abiquo assigns role scopes to users
- All enterprises must now have a default scope for creating users
- Administrators can now create optional hierarchies of scopes and share resources, such as templates and specs, with tenants at lower levels of their hierarchies
|
|
Scope concepts
Concept_______ | Description | Notes |
---|
Scope | A list of resources (enterprises and/or datacenters) for access control |
|
---|
User scope | - The list of resources (datacenters and enterprises) that the user can view and manage.
- The user must also have the other required permissions (privileges and allowed datacenters)
| A user can deploy in allowed datacenters, even if they are not in their scope. An Administrator can manage users of the enterprises that are in their scope |
---|
Resource scope | - The list of enterprises whose users can access the resource, if they have the other required permissions
- Administrators select a set of scopes to share a resource with users of the enterprises listed in the scopes
| Used to share VM templates and VApp specs. An administrator can select their own scope, and scopes underneath their scope in the scope hierarchy |
---|
Scope hierarchy | - A parent scope and one or more child scopes
- Used for sharing resources to tenants that are underneath the administrator's scope
| Administrators can share VM templates and VApp specs with users in scopes beneath their own scope. But they cannot manage the enterprises that are not directly in their user scope |
---|
Global scope | The default scope for the cloud administrator that always includes all resources and cannot be modified |
|
---|
Unlimited scopes | - The global scope
- Use all enterprises checkbox selected - ALL current and future enterprises
- Use all datacenters checkbox selected - ALL current and future datacenters
| An unlimited scope cannot have a parent scope. It must be at the top of a scope hierarchy. An unlimited scope has new resources added automatically in its unlimited dimensions. Only a user with an unlimited scope can create an unlimited scope in the same dimensions as their scope. |
---|
Pricing scope | - When a user creates a pricing model, the platform assigns the user's scope for tenants.
- Only users with the same tenant scope can manage the pricing models
- All users with pricing privileges can view the pricing model of their tenant
| You cannot change the pricing scope or display it in the UI |
---|
The following screenshot shows a scope with enterprises and a child scope
...