Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

This section lists the privileges set in Abiquo and describes their function in the application. It also shows the privileges assigned to the default roles: CLOUD_ADMIN, ENTERPRISE_ADMIN, USER and OUTBOUND_API. No user can delete the default CLOUD_ADMIN role or change the role's permissions. There must always be at least one user with this role.

Unable to render {include} The included page could not be found.

Key to Info Column of Privileges Table

(star) = new privilege
(warning) = changed privilege
(minus) = deprecated privilege 

Privileges Table

 

Home privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

List enterprises within scopeENTERPRISE_ENUMERATEThis privilege allows a user to view the list of enterprises within scope and to view statistics for those enterprises

X

     
Allow user to switch enterpriseENTERPRISE_ADMINISTER_ALLThis privilege allows a user to change to another enterprise, in order to administer it, by clicking the switch user button in the Enterprises list

X

  

X

  
Display enterprise statisticsENTERPRISE_RESOURCE_SUMMARY_ENTThis privilege allows a user to filter statistics by enterprise to display the resources used by an enterprise in the enterprise resources panel

X

X

 

X

X

 
Display enterprise limits in statisticsENTERPRISE_SHOW_STATS_LIMITSThis privilege allows a user to view enterprise limits in addition to resources used in the enterprise resources panel if the user has the Display enterprise statistics privilege

X

X

X

   
Infrastructure privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Access Infrastructure viewPHYS_DC_ENUMERATEThis privilege allows a user to access the Infrastructure view and list the physical datacenters

X

  

X

  
Display resource usage panelPHYS_DC_RETRIEVE_RESOURCE_USAGEThis privilege allows a user to view the resource usage panel in the Infrastructure view

X

  

X

  
Manage datacenterPHYS_DC_MANAGEThis privilege allows a user to manage datacenters (add, edit and delete). Without it, the datacenter's properties will be read only

X

  

X

  
View datacenter detailsPHYS_DC_RETRIEVE_DETAILSThis privilege allows a user to go inside a datacenter and view its details (racks, physical machines, VLANs, storage and allocation rules)

X

  

X

  
Manage infrastructure elementsPHYS_DC_ALLOW_MODIFY_SERVERSThis privilege allows a user to manage infrastructure elements (add, edit and delete racks and physical machines)

X

  

X

  
Manage network elementsPHYS_DC_ALLOW_MODIFY_NETWORKThis privilege allows a user to manage network elements (add, edit and delete public VLANs)

X

     
Manage storage elementsPHYS_DC_ALLOW_MODIFY_STORAGEThis privilege allows a user to manage storage elements (add, edit and delete storage devices, pools, tiers and volumes)

X

     
Manage allocation rulesPHYS_DC_ALLOW_MODIFY_ALLOCATIONThis privilege allows a user to manage allocation rules (add and delete rules)

X

     
Manage datacenter backup configurationPHYS_DC_ALLOW_BACKUP_CONFIGThis privilege allows a user to manage backup configuration at datacenter level

X

  

X

  
Manage devicesMANAGE_DEVICESThis privilege allows a user to setup networking devices (Neutron)

X

     
Virtual datacenters privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Access virtual datacenters viewVDC_ENUMERATEThis privilege allows a user to access the Virtual Datacenters view

X

X

X

X

X

 
Manage virtual datacentersVDC_MANAGEThis privilege allows a user to manage virtual datacenters (add, edit and delete). Without it, the virtual datacenter details are read only

X

X

 

X

  
Manage virtual appliancesVDC_MANAGE_VAPPThis privilege allows a user to manage virtual appliances (add, edit and delete)

X

X

X

X

  
Manage virtual network elementsVDC_MANAGE_NETWORKThis privilege allows a user to manage private and public VLANS (add, edit and delete)

X

X

    
Manage virtual storage elementsVDC_MANAGE_STORAGEThis privilege allows a user to manage storage volumes (add, edit and delete)

X

X

    
Manage floating IPsMANAGE_FLOATINGIPSThis privilege allows a user to manage floating IPs (add and delete)

X

X

 

X

  
Manage firewallsMANAGE_FIREWALLSThis privilege allows a user to manage firewalls (add, edit and delete) for virtual datacenters

X

X

 

X

  
Manage load balancersMANAGE_LOADBALANCERSThis privilege allows a user to manage load balancers (add, edit and delete) for virtual datacenters

X

X

 

X

  
Manage virtual storage controllerVDC_MANAGE_STORAGE_CONTROLLERThis privilege allows a user to manage the controller of storage volumes

X

X

X

X

  
Manage public IPsMANAGE_PUBLICIPSThis privilege allows a user to manage public IPs for private virtual datacenters

X

X

X

   
Virtual appliances privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Edit virtual appliance detailsVAPP_CUSTOMISE_SETTINGSThis privilege allows a user to edit virtual appliance details (name, CPUs, etc.), go inside virtual appliances and view their details

X

X

X

X

  
Deploy and undeploy virtual appliancesVAPP_DEPLOY_UNDEPLOYThis privilege allows a user to deploy/undeploy virtual appliances

X

X

X

X

  
Perform virtual machine actionsVAPP_PERFORM_ACTIONSThis privilege allows a user to perform virtual machine actions (power on/off, pause, reboot, remote access)

X

X

X

X

  
Manage persistent templatesVAPP_CREATE_STATEFULThis privilege allows a user to manage persistent virtual machine templates (create in VApp; create, edit and delete in virtual datacenter)

X

X

X

X

  
Create instanceVAPP_CREATE_INSTANCEThis privilege allows a user to create instance templates of a virtual machine within a virtual appliance

X

X

X

   
Manage virtual machine hard disksMANAGE_HARD_DISKSThis privilege allows a user to access the virtual machine hard disk tab and manage hard disks (add and delete)

X

     
Manage layersVAPP_MANAGE_LAYERSThis privilege allows a user to manage anti-affinity layers in virtual appliances (create, edit and delete layers)

X

X

X

   
Manage virtual machine backup configurationVAPP_MANAGE_BACKUPThis privilege allows a user to access the backup configuration at virtual machine level and set the backup type and contents

X

     
Manage virtual machine backup scheduleVAPP_DEFINE_BACKUP_INFOThis privilege allows a user to specify an additional option for backup configuration by setting backup dates and times

X

     
Manage workflow tasksWORKFLOW_OVERRIDEThis privilege allows a user to start or cancel queued tasks if workflow is enabled

X

X

    
Delete unknown virtual machinesVAPP_DELETE_UNKNOWN_VMThis privilege allows a user to delete virtual machines in unknown state

X

     
Assign firewalls to virtual machinesASSIGN_FIREWALLSThis privilege allows a user to assign already created firewalls to virtual machines

X

X

    
Access persistent templates viewVAPP_STATEFUL_VIEWThis privilege allows a user to access the persistent virtual machine templates view

X

X

X

   
Manage virtual machine backup disksVAPP_MANAGE_BACKUP_DISKSThis privilege allows a user to specify disks and disk backup types (snapshot and complete)

X

X

    
Assign load balancersASSIGN_LOADBALANCERSThis privilege allows a user to assign load balancers

X

X

    
Manage virtual machine metricsUSERS_ENABLE_DISABLE_VM_METRICSThis privilege allows a user to activate monitoring of virtual machines

X

X

X

   
Access virtual machine metricsUSERS_SHOW_VM_METRICSThis privilege allows a user to manage monitoring

X

X

X

 

X

 
Restore virtual machine backupsVAPP_RESTORE_BACKUPThis privilege allows a user to restore virtual machine backups

X

X

    
Protect/unprotect virtual machinesVM_PROTECT_ACTIONThis privilege allows a user to protect/unprotect a virtual machine

X

     
Consume virtual appliance specsCONSUME_VAPP_SPECThis privilege allows a user to consume virtual appliance specs

X

  

X

  
Access alarms section in virtual machinesUSERS_VM_VIEW_ALARMSThis privilege allows a user to access alarms section within a virtual machine

X

     
Manage alarmsUSERS_VM_MANAGE_ALARMSThis privilege allows a user to manage alarms (create, edit and delete) within a virtual machine

X

     
Access alerts sectionUSERS_VAPP_VIEW_ALERTSThis privilege allows a user to access alerts section within a virtual appliance

X

     
Manage alertsUSERS_VAPP_MANAGE_ALERTSThis privilege allows a user to manage alerts (create, edit and delete) within a virtual appliance

X

     
Override virtual machine constraintsVM_EXCEED_CPU_RAMThis privilege allows a user to modify virtual machine CPU and RAM to values outside the maximum and minimum values defined in the virtual machine template

X

     
Edit virtual machine detailsVM_EDIT_CPU_RAMThis privilege allows a user to edit virtual machine details (CPU and RAM)

X

X

X

X

X

 
Retrieve default VM credentialsVM_CHECK_USER_PASSWORDThis privilege allows a user to retrieve the default user and password of a virtual machine

X

     
Access action plans and task schedules viewsVM_ACTION_PLAN_VIEWThis privilege allows a user to access action plans and task schedules views

X

     
Manage action plans and task schedulesVM_ACTION_PLAN_MANAGEThis privilege allows a user to manage action plans and task schedules

X

     
Relocate a VM to a compatible hostVM_RELOCATEThis privilege allows a user to relocate a VM to a compatible host

X

    (star) 3.10.1
Manage workflow for scaling groupsSCALING_GROUP_MANAGE_WORKFLOWThis privilege allows a user to enable or disable workflow for scaling groups.

X

    (star)
Attach NICs in restricted networksVM_ATTACH_NICThis privilege allows a user to attach NICs in restricted networks

X

    (star)
Detach NICs from restricted networksVM_DETACH_NICThe privilege allows a user to detach NICs from restricted networks

X

    (star)
Manage scaling groupsMANAGE_SCALING_GROUPSThis privilege allows a user to manage scaling groups (add, edit and delete)

X

    (star)
Apps library privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Access Apps library viewAPPLIB_VIEWThis privilege allows a user to access the Appliance library view

X

X

 

X

  
Manage VM templates from Apps libraryAPPLIB_ALLOW_MODIFYThis privilege allows a user to view the Appliance library contents, modify virtual machine templates (download from remote repositories, edit and delete) and promote instances

X

X

 

X

  
Upload virtual machine templateAPPLIB_UPLOAD_IMAGEThis privilege allows a user to upload virtual machine templates from a local file into the Apps library

X

X

 

X

  
Manage repositoryAPPLIB_MANAGE_REPOSITORYThis privilege allows a user to manage repositories (add and delete repositories)

X

X

    
Download virtual machine templateAPPLIB_DOWNLOAD_IMAGEThis privilege allows a user to download virtual machine templates from the Appliance library to their hard disk

X

X

 

X

  
Manage VM template categoriesAPPLIB_MANAGE_CATEGORIESThis privilege allows a user to manage categories of virtual machine templates that belong to their enterprise (add and delete)

X

X

    
Manage VM template global categoriesAPPLIB_MANAGE_GLOBAL_CATEGORIESThis privilege allows a user to manage categories of virtual machine templates that are common and available to all enterprises (add and delete)

X

     
Display datacenter capacity and free spaceAPPLIB_SHOW_DC_CAPACITYThis privilege allows a user to view the capacity and remaining space of a datacenter

X

     
Export a virtual machine template to datacenterAPPLIB_EXPORT_TO_PRIVATEThis privilege allows a user to export a virtual machine template to another private datacenter.

X

     
Export a virtual machine template to public cloud regionAPPLIB_EXPORT_TO_PUBLICThis privilege allows a user to export a virtual machine template to another public cloud region.

X

     
Manage virtual appliance specsMANAGE_VAPP_SPECThis privilege allows a user to manage virtual appliance specs (add and edit)

X

     
Download VM templates from remote repositoryAPPLIB_DOWNLOAD_FROM_REMOTE_REPOSITORYThis privilege allows a user to download virtual machine templates from remote repositories

X

X

    
Users privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Access Users viewUSERS_VIEWThis privilege allows a user to access the Users view

X

X

 

X

  
Manage enterprisesUSERS_MANAGE_ENTERPRISEThis privilege allows a user to manage enterprises (add, edit and delete)

X

  

X

  
Manage usersUSERS_MANAGE_USERSThis privilege allows a user to manage users (add, edit and delete)

X

X

 

X

  
Manage users of all enterprisesUSERS_MANAGE_OTHER_ENTERPRISESThis privilege allows a user to manage users of more than one enterprise and move users between enterprises. Without it, the Enterprise list is not shown in Users view

X

  

X

  
No VDC restrictionUSERS_PROHIBIT_VDC_RESTRICTIONNormally a user within an enterprise can have a list of VDCs assigned and these will be the only VDCs that they will be able to see. Setting this privilege exempts a user from having their VDC list restricted and they will be able to see all VDCs in their enterprise

X

X

 

X

  
Access Roles screenUSERS_VIEW_PRIVILEGESThis privilege allows a user to access the Roles screen

X

  

X

  
Manage rolesUSERS_MANAGE_ROLESThis privilege allows a user to manage roles (add, edit and delete roles; modify privileges assigned to roles; assign scopes to roles)

X

     
Associate role with enterpriseUSERS_MANAGE_ROLES_OTHER_ENTERPRISESThis privilege allows a user to associate a role with any enterprise

X

     
Manage global roleUSERS_MANAGE_SYSTEM_ROLESThis privilege allows a user to manage roles that are common and available to all enterprises, rather than being constrained to a single enterprise

X

     
Specify LDAP groupUSERS_MANAGE_LDAP_GROUPThis privilege allows a user to associate a role with an LDAP group. When LDAP authentication is activated, a user's role will be determined by the LDAP group that they are a member of

X

     
Display connected usersUSERS_ENUMERATE_CONNECTEDThis privilege allows a user to display connected users

X

     
Define enterprise managerUSERS_DEFINE_AS_MANAGERThis privilege defines a user as an enterprise manager. Enterprise managers receive physical machine notification emails

X

X

    
Manage Chef enterprisesUSERS_MANAGE_CHEF_ENTERPRISEThis privilege allows a user to enable and manage Chef for enterprises

X

     
Manage scopesUSERS_MANAGE_SCOPESThis privilege allows a user to manage scopes (add, edit and delete scopes)

X

     
Manage enterprise reserved serversUSERS_MANAGE_RESERVED_MACHINESThis privilege allows a user to manage reserved servers at enterprise level

X

  

X

  
Modify enterprise themeUSERS_MANAGE_ENTERPRISE_BRANDINGThis privilege allows a user to manage enterprise branding (select a specific theme for an enterprise)

X

     
Allow user to push own VM metricsUSERS_PUSH_VM_METRICSThis privilege allows a user to push their own VM metrics

X

X

X

   
Manage provider credentialsUSERS_MANAGE_CREDENTIALSThis privilege allows a user to manage provider credentials (add and delete)

X

     
Manage user applicationsUSERS_MANAGE_APPLICATIONSThis privilege allows a user to manage applications (add and delete)

X

     
System configuration privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Access Configuration viewSYSCONFIG_VIEWThis privilege allows a user to access the Configuration view

X

  

X

  
Modify configuration dataSYSCONFIG_ALLOW_MODIFYThis privilege allows a user to edit all system-wide configuration settings

X

     
Allow access to reportsSYSCONFIG_SHOW_REPORTSThis privilege allows a user to access external reports by clicking the Reports button. The button will only be visible if the 'Reports URL' system property is not empty (Configuration -> System Properties -> General -> Reports URL)

X

     
Pricing privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Add a cost code when editing a VM templateAPPLIB_VM_COST_CODEThis privilege allows a user to select a cost code when editing a virtual machine template

X

     
Access Pricing viewPRICING_VIEWThis privilege allows a user to access the Pricing view

X

  

X

  
Manage pricingPRICING_MANAGEThis privilege allows a user to manage pricing components (add, edit and delete currencies, pricing models and cost codes)

X

     
Events privileges
        

GUI Label _________________

Application Tag

Privilege____________________________________

Cloud Admin

Ent Admin

Ent User

Outbound API

Ent Viewer

Info

Display all events for current enterpriseEVENTLOG_VIEW_ENTERPRISEThis privilege allows a user to display all events related to the current enterprise

X

X

X

 

X

 
Display all eventsEVENTLOG_VIEW_ALLThis privilege allows a user to display all events

X

     
  • No labels