Role-Based Access Control

The Role-Based Access Control (RBAC) policy framework enables both operators and users to grant access to resources for specific projects or tenants. Prior to RBAC, Neutron applied an all-or-nothing approach to the sharing of networks across projects. If a network was marked as shared, it was shared with all projects. Access control policies built using the Neutron RBAC API allow operators and users to share certain network resources with one or more projects using a more granular approach.

As of the Pike release of OpenStack, access that can be granted using access control policies includes the following:

  • Regular port creation permissions on networks
  • Attaching router gateways to networks
  • Binding Quality of Service ...

Get Learning OpenStack Networking - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.