Skip to main content

Manage access to cloud server placement groups

Access to cloud server placement groups is governed by a role model that defines access within an account and project. Read more in the Access Control in Servercore Products instruction.

member

A user with full access to all services. Does not have access to manage: users, service users, user groups, and federations.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available cloud server placement group operations

In the Account access scope:

  • viewing quotas for all projects (default quotas);

  • viewing the list of placement groups and their information: group name, placement policy condition;

  • managing placement groups:

    • creating placement groups;
    • deleting placement groups;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;

  • viewing the list of SSH keys and their information

In the Project access scope:

  • viewing project quotas (default quotas);

  • viewing the list of placement groups and their information: group name, placement policy condition;

  • managing placement groups:

    • creating placement groups;
    • deleting placement groups;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;

  • viewing the list of SSH keys and their information

reader

A user with access to view everything that member manages in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available cloud server placement group operations

In the Account access scope:

  • viewing quotas for all projects (default quotas);
  • viewing the list of placement groups and their information: group name, placement policy condition;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and their information

In the Project access scope:

  • viewing project quotas (default quotas);
  • viewing the list of placement groups and their information: group name, placement policy condition;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and their information

iam.admin

A user with access to manage users, but without access to services and billing. Cannot manage their own account: change permissions, manage notifications, or delete a user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available cloud server placement group operations

iam.viewer

A user with access to view everything that the iam.admin manages.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations with cloud servers and flavors

compute.server_group.admin

User with access to manage cloud server placement groups. Does not have access to other products.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available cloud server placement group operations

In the Account access scope:

  • viewing quotas for all projects (default quotas);

  • viewing the list of placement groups and their information: group name, placement policy condition;

  • managing placement groups:

    • creating placement groups;
    • deleting placement groups;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;

  • viewing the list of SSH keys and their information

In the Project access scope:

  • viewing project quotas (default quotas);

  • viewing the list of placement groups and their information: group name, placement policy condition;

  • managing placement groups:

    • creating placement groups;
    • deleting placement groups;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;

  • viewing the list of SSH keys and their information

compute.server_group.viewer

User with access to view cloud server placement groups. Does not have access to other products.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available cloud server placement group operations

In the Account access scope:

  • viewing quotas for all projects (default quotas);
  • viewing the list of placement groups and their information: group name, placement policy condition;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and their information

In the Project access scope:

  • viewing project quotas (default quotas);
  • viewing the list of placement groups and their information: group name, placement policy condition;
  • viewing the list of flavors and their information: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and their information