Domain Resource Sharing
Domain resource sharing principles
When OneCloud has three-level permissions enabled, the following domain resources support sharing. When three-level permissions are disabled, domain resources do not support sharing.
- Hosts, physical machines, block storage, cloud accounts, proxies, Layer-2 networks, VPCs, NAT gateways, DNS, and more.
Sharing principles
- If a domain resource is synced from a cloud account, its sharing is tied to the cloud account.
- When the cloud account is not shared, resources synced from it cannot be shared either.
- When the cloud account enables sharing, resources synced from it also enable sharing along with the cloud account.
- When the cloud account enables sharing, resources synced from it can change their sharing scope; ensure the scope stays within the cloud account’s sharing scope.
- When the cloud account changes its sharing scope, the sharing scope of resources synced from it must always remain within the cloud account’s sharing scope. For example, if the cloud account is shared with domains A, B, C, and D, and the domain resource is shared with domains A and C, then after the cloud account sharing scope is changed to A and B, the domain resource can only be shared with domain A.
- When the cloud account shares cloud subscriptions, domain resources synced from it cannot be shared.
- The sharing scope of local storage must always match the sharing scope of the host.
Set sharing
The following uses hosts as an example to describe how to set the sharing scope of a host.
Domain resources have three sharing scopes:
- Not shared (private): Only users in the same domain can use the domain resource.
- Domain share - partial (multi-domain share): The domain resource can be shared with one or more specified domains. Only users in the owning domain and the shared domains can use it.
- Domain share - all (global share): The domain resource can be shared with all domains, so all users in the system can use it.
Note
Conditions for setting sharing (all must be met):
- The current user is in the Admin Console.
- Three-level permissions are enabled on OneCloud.
Set sharing for a single host
- In the left navigation bar, choose “Resource Management/Compute/Basic Resources/Hosts” to open the Hosts page.
- Click “More” in the Actions column for the host, then choose “Set Share” from the drop-down menu to open the set sharing dialog.
- Configure the following parameters:
- When the sharing scope is “Not shared”, the domain resource is private and only users in the same domain can use it.
- When the sharing scope is “Domain share”, select the domains to share with.
- When one or more domains are selected, the scope is Domain share - partial; only users in the owning domain and the shared domains can use the domain resource.
- When all domains are selected, the scope is Domain share - all; all users in the system can use the domain resource.
- Click “OK” to complete the operation.
Set sharing in bulk
- In the left navigation bar, choose “Resource Management/Compute/Basic Resources/Hosts” to open the Hosts page.
- In the host list, select one or more hosts, click “Batch Actions” above the list, then choose “Set Share” from the drop-down menu to open the set sharing dialog.
- Configure the following parameters:
- When the sharing scope is “Not shared”, the domain resource is private and only users in the same domain can use it.
- When the sharing scope is “Domain share”, select the domains to share with.
- When one or more domains are selected, the scope is Domain share - partial; only users in the owning domain and the shared domains can use the domain resource.
- When all domains are selected, the scope is Domain share - all; all users in the system can use the domain resource.
- Click “OK” to complete the operation.