Account management
4.2.2 Account management
AccountingThe VirtOn It's a key feature for efficiently managing the user accounts that use the system, and the administrator can add new accounts on this screen, modify the information on the existing accounts, and manage user roles.
4.2.2.1 Added account
- Account ID: Only English, numbers, hyphen, and sub-bar are available, and you can click on the Copy check after you enter.
- If there's a duplicate ID, it can't be generated with a message whether it exists or not.
4.2.2.2 Selection of roles
- Role selection
- Manager: What is it? Cluster building, HA setting, storage management, VM/CT Full lifecycle management
- I'm not going to lie. User/monitoring account only managed by the part manager (ADMIN Super_Admin is uncontrollable.)
- Members: Operating and specification modification permissions for assigned resources
- Monitoring: You can only view the dashboard, the resources, the alert page.
4.2.2.3 Password
- Password: The password policy is the same as above, and it's verified in real time when you enter it, and it's generated when all the conditions are met.
- You can check the password you entered when you click the right eye-shaped icon.
4.2.2.4 Management of the
The management area is Change the password, Change of role, Reset the password., Delete itThere you go. I mean, Role changes, password reset, deletion functionalityThe The manager.But we can control it.
4.2.2.4.1 Changing the password
- Change the password: You enter your existing password and you validate the new password in real time by applying the same password policy.
- Changing the password Change your account only. It's possible. (Change after logging in directly to the account)
4.2.2.4.2 Changes of role
- The role change is The manager.It's only controllable. Role(role) By changing the The power increase Or Down the power. We can do that.
- When you change roles, the default permissions for that account change.
4.2.2.4.3 Reset the password
- The password reset is The manager.It's only controllable. Initiate the password for another account. I'm going to do it. Provisional passwords are issued.I get it.
- You copy the temporary password you've issued and you pass it on to that account.
- The account you're sending is logging in with a temporary password and changing the password.
4.2.2.4.4 deleted
- Delete the function The manager.You can just delete other settings.
4.2.3 Authorization management
Authorization managementBy user Role(Role)The key security feature is to configure and control system access and control permissions accordingly.(ADMIN, CUSTOM, USER, VIEWER) So you can sort it into a list of things that you can manage intuitively.
4.2.3.1 Role(Role) Other default permissions list(Permitted functional range)
<div class="perm-table">
| Functional category | Detailed feature items | Super manager, please.(super admin) | The manager.(admin) | Members(User) | Monitoring(viewer) |
|---|---|---|---|---|---|
| Account and security | User registration/delete and authorization | ✅ | ✅ | - | - |
| Proxmox API Connection and password setting | ✅ | ✅ | - | - | |
| Pool management(Create/delete/connect/share the resource) | ✅ | ✅ | - | - | |
| Cluster management | Create a cluster and add new nodes directly | ✅ | ✅ | - | - |
| Cluster network and link setup | ✅ | ✅ | - | - | |
| The price of the product (HA) | The role of the HA node(CRM) and Quorum Status Management | ✅ | ✅ | - | - |
| HA Resources(VM/CT) Additional and advanced settings | ✅ | ✅ | - | - | |
| Infrastructure and network | Ceph Storage.(OSD/MDS) State of the art. | ✅ | ✅ | - | - |
| Create/fix/delete the network interface | ✅ | ✅ | - | - | |
| Instantaneous control | VM / CT New creation and deletion | ✅ | ✅ | - | - |
| Instance power control (Start/Mid/Return) | ✅ | ✅ | ✅ | - | |
| Console connection (VNC connection and key transfer) | ✅ | ✅ | ✅ | - | |
| Modified resource specification (CPU Changed memory.) | ✅ | ✅ | ✅ | - | |
| Data protection | Template conversion and node-to-node migration | ✅ | ✅ | - | - |
| Backup creation/recovering/delete and protection settings | ✅ | ✅ | ✅ | - | |
| Create/rollback/delete the snapshot(RAM Included Selection) | ✅ | ✅ | ✅ | - | |
| Monitoring and logging | Overview of the entire dashboard and resource usage | ✅ | ✅ | ✅ | ✅ |
| A real-time alert(Alert) And Ceph Check the health. | ✅ | ✅ | ✅ | ✅ | |
| I'm going to check your credit history. | ✅ | ✅ | - | - | |
| General system settings | ✅ | ✅ | - | - |
</div>
4.2.3.1.1 Basic permissions assigned to each account role
1. The newly added account is not a role, but a basic functional privilege. Only the Super Manager, the Administrator account is controlled. 2. The administrator accountIt has most of the operating privileges, but some of the Super administrator exclusive authority(Examples: authority management, system initialization/upgrading related) Silver is excluded.
- You can check the account list for the roles and permissions of each account when you select an account.
4.2.3.2 Add and delete roles
- You can check the default permissions assigned to each category and they're marked as default permissions.
4.2.3.2.1 Delete the default permissions(Only the manager.)
- You can remove the permissions by clicking the X button on the list of functional categories.
- Delete permissions are removed from permissions with the + button.
4.2.3.2.2 Added default permissions(Only the manager.)
- If you add back the default permissions that were removed, they'll be re-allocated along with the default permissions.
4.2.3.2.3 CUSTOM account
- Customs is the way.(CUSTOM) Roles are the most flexible accounting rankings that managers can freely assemble their authority in a specific operating environment or within the scope of their work.
- A complete unauthorized state with no basic permissions at the beginning of account creation.(Authorisation: 0) It starts with.
- System administrators have individual access permissions that are essential to the user in the detailed categories of 'Accounting and Security', 'Cluster Management', etc.(Example: user registration, role changes, etc.) Add to right(+) You can manually assign or cancel only the necessary permissions using the button.
4.2.3.3 Prohibition of control of non-managemental authority management
- If the account is not an administrator, it will be shown that it has no control permissions and it will be uncontrollable. (Current access example: Monitoring role account)
4.2.4 Pool management
- Pool management The function is to link the resource access range to Pool units and manage Pool roles by user.
- You can create a pool on the screen, connect/unplug a resource, assign/unplug a user pool, delete a pool.
4.2.4.1 Pool creation and listing
4.2.4.1.1 Creating a new pool
- Up on the right. [+ new pool] It's generated by a button.
- Enter the entry:
- Pool name(It's necessary.)
- Explanation(Choice)
- You can't create a pool with the same name if it already exists.
4.2.4.1.2 Information that can be verified in the list
- Pool name / description
- Number of members
- Number of resources
- The day of creation.
4.2.4.2 Main management work
4.2.4.2.1 Connecting the resource
- After the pool card expansion Resource connection Type and identify in the area and connect.
- Type of connectivity:
- VM/CT
- The network.
- Storage.
- Identifier format:
- VM/CT:
nodeId:qemu|lxc:vmid(Yes, I know.phum03:qemu:101) - Network:
nodeId:iface(Yes, I know.phum03:vmbr0) - Storage:
storageId(Yes, I know.local-lvm)
- VM/CT:
- Resource identifiers can only enter one at a time, and resources that are already connected to other Pools cannot be duplicated.
4.2.4.2.2 Ressource disconnect
- Connection resource to the right. [X] I'll undo it with a button.
4.2.4.2.3 User role allocation/solution
- The user is assigned to the pool card as an additional icon.
- Pool roles assigned:
- Pool manager (POOL_ADMIN)
- Pool operator (POOL_OPERATOR)
- User role list on the right [X] You can undo the role with a button.
4.2.4.3 Pool deleted
- You can delete the pool card with the right hand side of the handkerchief icon.
- When deleted, the user role mapping of the respective Pool is deleted along with the resource mapping.
4.2.4.4 Pool Role-Based Access and Control Range
- Limitations on roles:
ADMIN,SUPER_ADMINYou can't assign Pool to the account.
4.2.4.4.1 Pool operator (POOL_OPERATOR)
- Instantly controlled:
vm.power,vm.start,vm.stop,vm.console,vm:resource-modify - Network/story access is available.
- Backup/Snapshot: Created/Redirected/Recoverable, not deleted
4.2.4.4.2 Pool manager (POOL_ADMIN)
- Instantaneous/Network/Storage Viewing + Correction(RU) It's possible.
- Network/storage cannot be created/deleted
- Backup/Snapshot: Created/Redirected/Redirected/Deleted