Fuzzball Documentation
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Group Management

Once users have been added into your Fuzzball deployment under an organization as described in the Adding Users to Organizations section, you can begin controlling their access to resources such as storage volumes, group secrets, and compute resource definitions through the groups entity. This section will walk through various Fuzzball group subcommands which can be used to manipulate Fuzzball groups within an organization.

TaskCommand
Create a groupfuzzball group create
Add users to a groupfuzzball group member add
Remove users from a groupfuzzball group member remove
Delete a groupfuzzball group delete
List group membersfuzzball group member list
Select the current group contextfuzzball group use
Manage the compute policyfuzzball group compute-policy get|add|remove|set

Selecting the Current Group

Group-scoped subcommands operate on the currently-selected group: fuzzball group compute-policy uses it when no GROUP positional is supplied, and fuzzball group set-object-ttl / get-object-ttl always use it. Select a group as the CLI’s current context with fuzzball group use:

$ fuzzball group use my-group

Subsequent group-scoped commands operate on my-group until you switch again. Workflow submissions from that CLI context also inherit this group binding, so switching groups is the supported way to submit under a specific group when a user belongs to several.

Group and Organization Scoping

Switching your current group does not widen what you can reach. Object TTL configuration is authorized against the group or organization the request targets, and that target must be within your own organization:

  • fuzzball org set-object-ttl and get-object-ttl only ever apply to the organization your credentials belong to. Changing the setting requires organization ownership; reading it requires organization membership.
  • fuzzball group set-object-ttl and get-object-ttl apply to your currently-selected group, which you must already be a member of.

Requests that target a group or organization outside your own are rejected with a permission error, even when your credentials are otherwise valid.

Listing Group Members

You can list members of a group using the fuzzball group member list command.

Filtering by Role

The --owner flag controls filtering by member role:

# List all members (owners and non-owners)
$ fuzzball group member list <group-name>

# List only owners
$ fuzzball group member list <group-name> --owner

# List only non-owners
$ fuzzball group member list <group-name> --owner=false
Default behavior: When no flag is provided, the command lists all members (both owners and non-owners).

Deprecated Flag

The --relationship flag is deprecated in favor of --owner. If you have scripts using the old flag, update them to use the new syntax:

Old syntaxNew syntax
--relationship=all(omit flag)
--relationship=owner--owner
--relationship=member--owner=false
The --relationship flag will be removed in a future release. Update your scripts to use --owner.