# ACL Virtual machine permissions based on Cluster

**URL:** <https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523>\
**Category:** Installation & Configuration\
**Created:** [June 10, 2020, 9:30am UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523 "2020-06-10T09:30:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bram\_Fransen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/bram_fransen/32/6441_2.png) [@Bram\_Fransen](https://forum.opennebula.io/u/Bram_Fransen)\
**Post date:** [June 10, 2020, 9:30am UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/1 "2020-06-10T09:30:40Z")

</div>

Hey,

Is there any solution to give a group use/mange permissions for virtualmachines within Cluster ID?

 ![image](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/d/d4b966260945878081768b3f7a4aaa16797acb63.png)  
I get a error message when apply this setting:  
CLUSTER(%) selector can be applied only to DATASTORE, HOST and NET types

---

<div class="post-metadata">

**Author:** ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)\
**Post date:** [June 12, 2020, 9:40am UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/2 "2020-06-12T09:40:48Z")

</div>

Hi,

I’m afraid that is not possible. You can impose cluster-based restrictions to objects that are part of a cluster. (hosts, datastores or networks).

VM access restrictions can be imposed based on group ownership

---

<div class="post-metadata">

**Author:** ![Bram\_Fransen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/bram_fransen/32/6441_2.png) [@Bram\_Fransen](https://forum.opennebula.io/u/Bram_Fransen)\
**Post date:** [June 12, 2020, 10:48am UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/3 "2020-06-12T10:48:04Z")

</div>

Okey… Another use case:  
Every user is a ldap user and i have multiple groups:

Admins\_group ( ldap based)

- mange permissons on every vm within cluster.

User\_group (local groups manual action)

- users are added to this group to use (1 or more vm`s)

How can i accomplice this?

---

<div class="post-metadata">

**Author:** ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)\
**Post date:** [June 15, 2020, 11:51am UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/4 "2020-06-15T11:51:00Z")

</div>

I think the best approach in your case is Virtual Datacenters ([https://docs.opennebula.io/5.10/operation/users\_groups\_management/manage\_vdcs.html](https://docs.opennebula.io/5.10/operation/users_groups_management/manage_vdcs.html))

You can:

- Create a VDC and associate a cluster to it
- Create a group of users associated to this VDC
- Create a group-admin to act as a tier-1 admin for the group with permission over user management and group resources.

---

<div class="post-metadata">

**Author:** ![Bram\_Fransen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/bram_fransen/32/6441_2.png) [@Bram\_Fransen](https://forum.opennebula.io/u/Bram_Fransen)\
**Post date:** [June 15, 2020, 12:22pm UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/5 "2020-06-15T12:22:18Z")

</div>

Something like this? I dont see any vm`s when im user of admin group.  
ACL:

 ![image](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/c/c4ecadf3534a8568b588832b188f25ff72839038.png)  
VDC:  
 ![image](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/8/8ef9636233f7090f0e35a19f14d63d2f86200b81.png)

---

<div class="post-metadata">

**Author:** ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)\
**Post date:** [June 15, 2020, 12:47pm UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/6 "2020-06-15T12:47:14Z")

</div>

There should be an ACL (automatically created) that allow group admins to manage resources in the group as the group only have access to a cluster you should get (to some extent) the behavior you are looking for.

Create a group and a group admin  
Then create a VDC for this group and clusters you like.

ACLs should look like this:

 ![vdc-acls](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/5/5bfa2be65117a62a69f21059c9fdabed50d57489.png)

As you see the admin has manage rights over the test\_group resources

---

<div class="post-metadata">

**Author:** ![Bram\_Fransen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/bram_fransen/32/6441_2.png) [@Bram\_Fransen](https://forum.opennebula.io/u/Bram_Fransen)\
**Post date:** [June 15, 2020, 12:57pm UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/7 "2020-06-15T12:57:52Z")

</div>

Sorry maybe i`m doing somethings wrong 😕

 ![image](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/c/c6b1369edd5d0ac7dd8da7d8d25fa02202a0a0ab.png)

 ![image](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/0/0fc041fe353488ce86a26b3a1793ba0250016360.png)  
Nothing found when i`m logged as admin user.  
 ![image](https://canada1.discourse-cdn.com/flex031/uploads/opennebula/original/2X/1/1b6ae9f98aff446c2ced8891b611ef4a573543ea.png)

---

<div class="post-metadata">

**Author:** ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)\
**Post date:** [June 15, 2020, 1:50pm UTC](https://forum.opennebula.io/t/acl-virtual-machine-permissions-based-on-cluster/8523/8 "2020-06-15T13:50:06Z")

</div>

No, you are not doing anything wrong. This is the “to some extent” I refer to. THe VM is owned by oneadmin, this is only going to work for the VMs created within the VDC i.e. by people on the VDC group.
