Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Previous page: Catalogue

Next page: Pricing

Info

This document is part of the Abiquo walkthrough.

It describes how to manage tenants (enterprises), users, and their permissions and access in the cloud platform (roles and scopes).

The previous page is Catalogue and the next page is Pricing

The Users tab is where a Cloud Admin will define the enterprises (or cloud tenants) that can use the Abiquo cloud. For example, for an enterprise creating a private cloud the enterprises will be departments, project teams or cost centers. For a service provider the enterprises will be customers of the cloud service (including resellers).

...

Expand
titleClick here to show/hide the task: Create an enterprise for a cloud tenant to consume cloud resources

To create an enterprise for a cloud tenant to consume cloud resources:

  1. Log in as SysAdmin

  2. From the Users pane click + to add the new enterprise

  3. Enter the enterprise Name (the Enterprise logo and theme are optional)

Image Removed
  1. Image Added
  2. Go to Datacenters and select a datacenter for the enterprise to use. Move the datacenter, or public cloud provider or region to the Allowed datacenters list.

Image Removed
  1. Image Added


  2. Click Save  

When creating a new enterprise, the Cloud Admin can define exactly how that enterprise can use the infrastructure. So while the enterprise will have a self-service experience, the Cloud Admin remains in control and defines the boundaries of what the enterprise can do.

...

Expand
titleClick here to show/hide the task: Reserve servers for a tenant

To set limits based on the business agreement with the Enterprise holder

  1. Log in as SysAdmin

  2. In Users view, select a specific enterprise

  3. Select Edit and go to Reservations

  4. Select a datacenter and rack where a server will be reserved for this enterprise

  5. Move one of the available servers to add the server to the Reserved servers list.

Image Removed
  1. Image Added
  2. Log in as ANY user NOT in this enterprise (note rack reserved servers should not be available).

  3. Log in as ANY user in the enterprise with the reserved server.

Within an enterprise, Admins create users with roles. Roles can have over 100 granular privileges and you can base them on the Abiquo default roles for Cloud Admin, Enterprise Admin (tenant admin), and User. The Cloud Admin can therefore delegate as much, or as little administration as they require. Or they can create roles for specific administrative functions (e.g a Network Admin). You can link Abiquo roles to those in an external directory system such as LDAP, AD, or OpenID.

...

Expand
titleClick here to show/hide the task: Delegate administration of the enterprise

 To create an enterprise Admin user do these steps:

  1. Log in as SysAdmin

  2. Select a specific enterprise

  3. Go to the Users pane and click + to add the new user

  4. Select the default role ENTERPRISE_ADMIN

  5. Select Global scope

Image Removed
  1. Image Added
  2. Go to the Advanced tab and enter user details as required

Image Removed
  1. Image Added
  2. Click Save

An Enterprise Admin user will be available. This user can manage template libraries and users for the enterprise.

...

Expand
titleClick here to show/hide the task: Create custom user roles

To create a custom user role:

  1. Login as SysAdmin

  2. Select UsersRoles

  3. Select the USER role and click the Clone button (or click + to add the new role)

  4. Fill in the necessary info. (External roles are not necessary at this time)

Image Removed
  1. Image Added
  2. Save the role

  3. Select the role again and select the required privileges, then click Save. See Manage Roles#Privileges table

  4. Create a new user and assign the new role to this user

The Admin can also define Administration scopes. These define groups of enterprises or data centers (Abiquo datacenters or public cloud regions) that can be administered by a user. This allows for more control over the infrastructure and it enables service providers to support a reseller model. Each reseller can manage a scope that is a list of their own customers. Admins can also create a scope hierarchy for sharing resources, such as VM templates and application blueprints, down a "tree branch" that includes the Admin's resellers, their customers and the customers' departments, and so on.