Doug Hellmann 9599ffe65d reorganize existing documentation according to the new standard layout
Move existing content around based on the doc-migration specification.

Replace :doc: markup with :ref: to have sphinx keep track of where the
files move and generate valid hyperlinks.

Add a few toctrees and index pages for the new directories.

Depends-On: Ia750cb049c0f53a234ea70ce1f2bbbb7a2aa9454
Change-Id: I253ee8f89d3ec40e39310c18bb87ed1d3d5de330
Signed-off-by: Doug Hellmann <doug@doughellmann.com>
2017-06-23 11:54:32 +02:00

6.5 KiB

role

Identity v2, v3

role add

Add role assignment to a user or group in a project or domain

role add

openstack role add
    --domain <domain> | --project <project> [--project-domain <project-domain>]
    --user <user> [--user-domain <user-domain>] | --group <group> [--group-domain <group-domain>]
    --role-domain <role-domain>
    --inherited
    <role>

--domain <domain>

Include <domain> (name or ID)

3

--project <project>

Include <project> (name or ID)

--user <user>

Include <user> (name or ID)

--group <group>

Include <group> (name or ID)

3

--user-domain <user-domain>

Domain the user belongs to (name or ID). This can be used in case collisions between user names exist.

3

--group-domain <group-domain>

Domain the group belongs to (name or ID). This can be used in case collisions between group names exist.

3

--project-domain <project-domain>

Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.

3

--inherited

Specifies if the role grant is inheritable to the sub projects.

3

--role-domain <role-domain>

Domain the role belongs to (name or ID). This must be specified when the name of a domain specific role is used.

3

<role>

Role to add to <project>:<user> (name or ID)

role create

Create new role

role create

openstack role create
    [--or-show]
    [--domain <domain>]
    <name>

--domain <domain>

Domain the role belongs to (name or ID).

3

--or-show

Return existing role

If the role already exists return the existing role data and do not fail.

<name>

New role name

role delete

Delete role(s)

role delete

openstack role delete
    <role> [<role> ...]
    [--domain <domain>]

<role>

Role to delete (name or ID)

--domain <domain>

Domain the role belongs to (name or ID).

3

role list

List roles

role list

openstack role list
    --domain <domain> | --project <project> [--project-domain <project-domain>]
    --user <user> [--user-domain <user-domain>] | --group <group> [--group-domain <group-domain>]
    --inherited

--domain <domain>

Filter roles by <domain> (name or ID)

(Deprecated if being used to list assignments in conjunction with the --user <user>, option, please use role assignment list instead)

--project <project>

Filter roles by <project> (name or ID)

(Deprecated, please use role assignment list instead)

--user <user>

Filter roles by <user> (name or ID)

(Deprecated, please use role assignment list instead)

--group <group>

Filter roles by <group> (name or ID)

(Deprecated, please use role assignment list instead)

--user-domain <user-domain>

Domain the user belongs to (name or ID). This can be used in case collisions between user names exist.

(Deprecated, please use role assignment list instead)

3

--group-domain <group-domain>

Domain the group belongs to (name or ID). This can be used in case collisions between group names exist.

(Deprecated, please use role assignment list instead)

3

--project-domain <project-domain>

Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.

(Deprecated, please use role assignment list instead)

3

--inherited

Specifies if the role grant is inheritable to the sub projects.

(Deprecated, please use role assignment list instead)

3

role remove

Remove role assignment from domain/project : user/group

role remove

openstack role remove
    --domain <domain> | --project <project> [--project-domain <project-domain>]
    --user <user> [--user-domain <user-domain>] | --group <group> [--group-domain <group-domain>]
    --role-domain <role-domain>
    --inherited
    <role>

--domain <domain>

Include <domain> (name or ID)

3

--project <project>

Include <project> (name or ID)

--user <user>

Include <user> (name or ID)

--group <group>

Include <group> (name or ID)

3

--user-domain <user-domain>

Domain the user belongs to (name or ID). This can be used in case collisions between user names exist.

3

--group-domain <group-domain>

Domain the group belongs to (name or ID). This can be used in case collisions between group names exist.

3

--project-domain <project-domain>

Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.

3

--inherited

Specifies if the role grant is inheritable to the sub projects.

3

--role-domain <role-domain>

Domain the role belongs to (name or ID). This must be specified when the name of a domain specific role is used.

3

<role>

Role to remove (name or ID)

role set

Set role properties

3

role set

openstack role set
    [--name <name>]
    [--domain <domain>]
    <role>

--name <name>

Set role name

--domain <domain>

Domain the role belongs to (name or ID).

3

<role>

Role to modify (name or ID)

role show

Display role details

role show

openstack role show
    [--domain <domain>]
    <role>

--domain <domain>

Domain the role belongs to (name or ID).

3

<role>

Role to display (name or ID)