Hide Forgot
Description of problem: One of our customer wants to configure RBAC for Active-Directory users accessing OpenStack dashboard to manage resources like instance & template creation, and multi-tenancy access etc. I have already provided following links: 1. https://access.redhat.com/documentation/en/red-hat-enterprise-linux-openstack-platform/7/users-and-identity-management-guide/chapter-1-user-and-role-management 2. https://access.redhat.com/documentation/en/red-hat-enterprise-linux-openstack-platform/7/users-and-identity-management-guide/chapter-3-identity-management#active-directory-integration But seems like they want exclusive documentation on RBAC + AD + Multi-tenancy. Version-Release number of selected component (if applicable): How reproducible: Steps to Reproduce: 1. 2. 3. Actual results: Expected results: Additional info:
Reviewing...
Customer also posted a use case which is simple hierarchical multi-tenancy: "After creating a new project and allocating some amount of resources, we should be able to create a hierarchy of users like Project Manager (PM) having complete view of the project usage, then PM should be able to allocate resources to different sub-teams (like Dev, QA, Prod, etc), each sub-team leads having access to their allocated resources and able to manage the resources at their level with approval from the PM. All the users will be AD authenticated ones."
As the customer need assistance on implementation, I have redirected him to the consulting team.I think the document will be too specific to customer needs. If documentation team still wants to work on this, feel free to re-open this RFE.
Re-opening RFE to document this use case, once this has been implemented: https://bugs.launchpad.net/keystone/+bug/1567446