Fuzzball Documentation
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Roles and Permissions

The table below illustrates the permissions of roles which can manipulate organizations and their membership.

ActionOrganization OwnerOrganization Member
Add Organization Ownerx
Add Organization Memberx
View Organization Membersxx

The table below illustrates the permissions of roles which can manipulate groups and their membership.

ActionOrganization OwnerGroup OwnerGroup Member
Create Groupx
Update Groupx
Delete Groupx
Add Group Ownerxx
Remove Group Ownerxx
View Group Ownersxxx
Add Group Memberxx
Remove Group Memberxx
View Group Membersxxx

The table below shows group roles and their ability to manipulate group and user scoped resources such as secrets, storage volumes, and compute resource definitions.

ResourceActionGroup OwnerGroup Member
Group Scoped ResourceCreatex
Updatex
Deletex
Accessxx
User Scoped ResourcesCreatexx
Updatexx
Deletexx
Accessxx

In the next section, we will walk through an example which ties the concepts of organizations, groups, and users together.

Node Provisioner Permissions

Node provisioners can be created and managed at different scopes within the organization hierarchy. The table below shows the permissions for node provisioner management.

ActionOrganization OwnerGroup OwnerGroup Member
Create Node Provisionerxx
Update Node Provisionerxx
Delete Node Provisionerxx
View Node Provisionersxxx

Organization-scoped node provisioners can be created and managed by organization owners. These node provisioners are available to all groups and users within the organization.

Group-scoped node provisioners can be created and managed by group owners. These node provisioners are available to members of that specific group, providing more granular control over which compute resources are accessible to different teams.

This hierarchical permission model allows administrators to delegate node provisioner management responsibilities while maintaining appropriate access controls across the organization.