5.3. Managing Domain Users

5.3.1. vinfra domain user list-available-roles

List available user roles:

usage: vinfra domain user list-available-roles

Example:

#  vinfra domain user list-available-roles
+---------------+---------------+--------------------------------------------+-----------+
| id            | name          | description                                | scope     |
+---------------+---------------+--------------------------------------------+-----------+
| abgw          | ABGW          | Can create and manage Acronis Backup       | - system  |
|               |               | Gateway.                                   |           |
| admin         | Administrator | Can perform all management operations.     | - system  |
| cluster       | Cluster       | Can create cluster, join nodes to cluster, | - system  |
|               |               | and manage (assign and release) disks.     |           |
| compute       | Compute       | Can create and manage compute cluster.     | - system  |
| domain_admin  | Domain Admin  | Can manage users, projects and all         | - domain  |
|               |               | resources in a domain.                     |           |
| image_upload  | Image Upload  | Can manage compute images.                 | - domain  |
| iscsi         | Block Storage | Can create and manage iSCSI targets, LUNs  | - system  |
|               |               | and CHAP users.                            |           |
| login         | Login         | Can login in web UI.                       | []        |
| network       | Network       | Can modify network settings and roles.     | - system  |
| nfs           | NFS           | Can create and manage NFS.                 | - system  |
| project_admin | Project Admin | Can manage virtual objects inside a        | - project |
|               |               | project.                                   |           |
| s3            | S3            | Can create and manage S3 cluster.          | - system  |
| ssh           | SSH           | Can add and remove SSH keys for cluster    | - system  |
|               |               | nodes access.                              |           |
| updates       | Updates       | Can install updates.                       | - system  |
| viewer        | Viewer        | Viewer role (read only)                    | - system  |
+---------------+---------------+--------------------------------------------+-----------+

This command lists all available user roles.

5.3.2. vinfra domain user create

Create a new domain user:

usage: vinfra domain user create [--email <email>] [--description <description>]
                                 [--assign <project> <role>]
                                 [--domain-permissions <domain_permissions>]
                                 [--system-permissions <system_permissions>]
                                 [--enable | --disable] --domain <domain> <name>
--email <email>
User email
--description <description>
User description
--assign <project> <role>

Assign a user to a project with one or more permission sets. Specify this option multiple times to assign the user to multiple projects.

  • <project>: project ID or name
  • <role>: user role in the project (project_admin)
--domain-permissions <domain_permissions>
A comma-separated list of domain permissions. View the list of available domain permissions using vinfra domain user list-available-roles | grep domain.
--system-permissions <system_permissions>
A comma-separated list of system permissions. View the list of available system permissions using vinfra domain user list-available-roles | grep system.
--enable
Enable user
--disable
Disable user
--domain <domain>
Domain name or ID
<name>
User name

Example:

#  vinfra domain user create --domain mydomain --name myuser \
--domain-permissions domain_admin
Password:
+--------------------+----------------------------------+
| Field              | Value                            |
+--------------------+----------------------------------+
| assigned_projects  | []                               |
| description        |                                  |
| domain_permissions | - domain_admin                   |
| email              |                                  |
| enabled            | True                             |
| id                 | a9c67c6acf1f4df1818fdeeee0b4bd5e |
| name               | myuser                           |
| role               | domain_admin                     |
| system_permissions | []                               |
+--------------------+----------------------------------+

This command creates and enables a new administrator account myuser within the domain mydomain. It also sets password for the new user.

5.3.3. vinfra domain user list

List all users in a domain:

usage: vinfra domain user list --domain <domain>
--domain <domain>
Domain name or ID

Example:

# vinfra domain user list --domain mydomain -c id -c name -c enabled \
-c domain_permissions -c assigned_projects
+-----------+--------+---------+-------------------+-------------------+
| id        | name   | enabled |domain_permissions | assigned_projects |
+-----------+--------+---------+-------------------+-------------------+
| a9c6<...> | myuser | True    |- domain_admin     | []                |
+-----------+--------+---------+-------------------+-------------------+

This command lists users in the domain mydomain. (The output is abridged to fit on page.)

5.3.4. vinfra domain user show

Display information about a domain user:

usage: vinfra domain user show --domain <domain> <user>
--domain <domain>
Domain ID or name
<user>
User ID or name

Example:

# vinfra domain user show myuser --domain mydomain
+--------------------+----------------------------------+
| Field              | Value                            |
+--------------------+----------------------------------+
| assigned_projects  | []                               |
| description        |                                  |
| domain_permissions | - domain_admin                   |
| email              |                                  |
| enabled            | True                             |
| id                 | a9c67c6acf1f4df1818fdeeee0b4bd5e |
| name               | myuser                           |
| role               | domain_admin                     |
| system_permissions | []                               |
+--------------------+----------------------------------+

This command shows the details of the user myuser from the domain mydomain.

5.3.5. vinfra domain user set

Modify the parameters of a domain user:

usage: vinfra domain user set [--password] [--email <email>]
                              [--description <description>]
                              [--assign <project> <role>]
                              [--domain-permissions <domain_permissions>]
                              [--system-permissions <system_permissions>]
                              [--enable | --disable] [--name <name>]
                              --domain <domain> <user>
--password
Request the password from stdin
--email <email>
User email
--description <description>
User description
--assign <project> <role>

Assign a user to a project with one or more permission sets. Specify this option multiple times to assign the user to multiple projects.

  • <project>: project ID or name
  • <role>: user role in the project (project_admin)
--domain-permissions <domain_permissions>
A comma-separated list of domain permissions. View the list of available domain permissions using vinfra domain user list-available-roles | grep domain.
--system-permissions <system_permissions>
A comma-separated list of system permissions. View the list of available system permissions using vinfra domain user list-available-roles | grep system.
--enable
Enable user
--disable
Disable user
--name <name>
User name
--domain <domain>
Domain name or ID
<user>
User ID or name

Example:

# vinfra domain user set myuser --domain mydomain \
--assign myproject project_admin
+--------------------+----------------------------------+
| Field              | Value                            |
+--------------------+----------------------------------+
| assigned_projects  | []                               |
| description        |                                  |
| domain_permissions | - domain_admin                   |
| email              |                                  |
| enabled            | True                             |
| id                 | a9c67c6acf1f4df1818fdeeee0b4bd5e |
| name               | myuser                           |
| role               | domain_admin                     |
| system_permissions | []                               |
+--------------------+----------------------------------+

This command assigns the user myuser from the domain mydomain to the project myproject as a project administrator.

5.3.6. vinfra domain user delete

Remove a domain user:

usage: vinfra domain user delete --domain <domain> <user>
--domain <domain>
Domain ID or name
<user>
User ID or name

Example:

# vinfra domain user delete myuser --domain mydomain
Operation successful

This command deletes the user myuser from the domain mydomain.