WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Xen and Enomaly

To: Olivier LAMBERT <lambert.olivier@xxxxxxxxx>
Subject: Re: [Xen-users] Xen and Enomaly
From: Thiago Camargo Martins Cordeiro <thiagocmartinsc@xxxxxxxxx>
Date: Fri, 11 Sep 2009 19:00:06 -0300
Cc: Grant McWilliams <grantmasterflash@xxxxxxxxx>, xen-users@xxxxxxxxxxxxxxxxxxx, Longina Przybyszewska <longina@xxxxxxxxxxxx>
Delivery-date: Fri, 11 Sep 2009 15:01:04 -0700
Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type; bh=8OMYY0Bp3S1xduD6Rz6PjmKM+bYtom/gSSZIBZtbXRQ=; b=XCeJvkRCvhAYC+1r3AxBqcwSNPONe8c3gsEPKBW4s+xd84VJ+dqczr8PGZg2b46ZVE xm03kAXI/WKyjeo57FWBChGulXMh1sRwQJzxDrB63AsQFQckq/zmMfSY4lVVNxgsUjkK sIgyhvsW/yvONi9pt8P+NLqnmc9PerE1e9GqM=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=BsFKoo9c/5+xQ6wFfWjnPE/A6QU4jhrPof5+6lJ0INYRCNoOoGP7sIqqi2cE/R7Te5 27MDkewD5BM6gvAcJfRpgSZHNjgHTHbgPivl4SdvpKm27v/xyAwfM0GTFI3HWGJB9orm VfU2dAOopy3jvvDk3v9dsUxTmqnONR2fX+RSg=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <f769216c0909111409o3030bbddo12796d9a79b8b97b@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <4AA91F4E.8040802@xxxxxxxxxx> <4AA9B495.5000708@xxxxxxxxxxxx> <6b7f6eb0909101944k7ecf3fbbwb9898d155a2b5667@xxxxxxxxxxxxxx> <alpine.DEB.2.00.0909111034220.15582@xxxxxxxxxxxxxxxxxxxx> <f769216c0909110201n2d052cfas7455b036ba70525b@xxxxxxxxxxxxxx> <f769216c0909110526h42fb80f2y9e61331617bb44b6@xxxxxxxxxxxxxx> <ed123fa30909110742p38b5c688l54a27533d22eeef8@xxxxxxxxxxxxxx> <f769216c0909110757x318ad857mbf5dce4c1a3f6a7f@xxxxxxxxxxxxxx> <ed123fa30909111349l30850efagbb08d60ec18d1cd6@xxxxxxxxxxxxxx> <f769216c0909111409o3030bbddo12796d9a79b8b97b@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
That's the way the Eucalyptus works!  :-D

2009/9/11 Olivier LAMBERT <lambert.olivier@xxxxxxxxx>
1) Yes, in the first step, the htaccess restrict only for the page :
after correct login, you can admin everything.
2) But your feature is an interesting one, so I'll do my best to
implement this functionality, seems to be able to that fast => sql
table with which user can view assigned VM (admin can view/edit every
VM, guest can only view and Bob can edit its "own" for example).

Thanks for your idea.

Regards,


Olivier.

On Fri, Sep 11, 2009 at 10:49 PM, Grant McWilliams
<grantmasterflash@xxxxxxxxx> wrote:
>>
>>
>> So, no root or other stuff like that. In my case, I choose to make
>> things simple : just an htaccess (so far).
>>
>> With the API, you've got access to the entire Xen daemon, but I think
>> it's not so hard to restrict an user to a VM (or more). It's "just" an
>> added layer, can be interfaced with ldap, mysql or pgsql database,
>> with adaquates informations on users.
>>
>> For your "feature request", I think I'll do, but in a first time, my
>> goal is to admin Xen easily. But ASAP, I'll try to respond to your
>> request.
>> And as it's a open source project, everyone can contribute, so.. more
>> we are, more the project will be great :)
>>
>> Regards,
>
> So currently you're using .htaccess to limit who can connect and control the
> VMs but if I understand you there's no limit what that person can do?
> If Bob (we like calling him Bob) logs into Orchestra he can restart ALL VMs?
> I don't know if this helps me any since I could just grant people sudo
> access to the xm command.
>
> If however you set it up so there's a database table that lists access
> rights and when creating a VM you assign admins to it this would be ideal.
> If Bob logs in your code would look up the database record to see what bob
> could do and restrict his actions to his own VM. Like you said I don't think
> this would be difficult code but for my project definitely needed. It's
> already very easy to start/stop domUs. I could set up a web page in about 30
> seconds that does the same thing (locally) without even using the API. I
> realize this is not what you're doing and that the project will grow but I'm
> hoping that this will be a feature you add fairly soon or I can if I have
> time. If I don't have that then it's no more useful than what I have now.
> :-)
>
> Grant McWilliams.
>

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>