Group Management
Once users have been added into your Fuzzball deployment under an organization as described in the Adding Users to Organizations section, you can begin controlling their access to resources such as storage volumes, group secrets, and compute resource definitions through the groups entity. This section will walk through various Fuzzball group subcommands which can be used to manipulate Fuzzball groups within an organization.
| Task | Command |
|---|---|
| Create a group | fuzzball group create |
| Add users to a group | fuzzball group member add |
| Remove users from a group | fuzzball group member remove |
| Delete a group | fuzzball group delete |
| List group members | fuzzball group member list |
| Select the current group context | fuzzball group use |
| Manage the compute policy | fuzzball group compute-policy get|add|remove|set |
Group-scoped subcommands operate on the currently-selected group:
fuzzball group compute-policy uses it when no GROUP positional is
supplied, and fuzzball group set-object-ttl / get-object-ttl always use
it. Select a group as the CLI’s current context with fuzzball group use:
$ fuzzball group use my-groupSubsequent group-scoped commands operate on my-group until you switch
again. Workflow submissions from that CLI context also inherit this group
binding, so switching groups is the supported way to submit under a specific
group when a user belongs to several.
Switching your current group does not widen what you can reach. Object TTL configuration is authorized against the group or organization the request targets, and that target must be within your own organization:
fuzzball org set-object-ttlandget-object-ttlonly ever apply to the organization your credentials belong to. Changing the setting requires organization ownership; reading it requires organization membership.fuzzball group set-object-ttlandget-object-ttlapply to your currently-selected group, which you must already be a member of.
Requests that target a group or organization outside your own are rejected with a permission error, even when your credentials are otherwise valid.
You can list members of a group using the fuzzball group member list command.
The --owner flag controls filtering by member role:
# List all members (owners and non-owners)
$ fuzzball group member list <group-name>
# List only owners
$ fuzzball group member list <group-name> --owner
# List only non-owners
$ fuzzball group member list <group-name> --owner=falseDefault behavior: When no flag is provided, the command lists all members (both owners and non-owners).
The --relationship flag is deprecated in favor of --owner. If you have scripts using the old flag, update them to use the new syntax:
| Old syntax | New syntax |
|---|---|
--relationship=all | (omit flag) |
--relationship=owner | --owner |
--relationship=member | --owner=false |
The--relationshipflag will be removed in a future release. Update your scripts to use--owner.