Settings


Sub-Account Setting


What is Sub-Account?

A sub-account can be created by the admin or synced from an SSO authentication system and is managed by the admin. Resources created under a sub-account are managed by the sub-account. You can use a sub-account to create and manage resources under its management and implement fine-grained control over the permissions on resources.

Concepts

  • admin: The admin has super privileges over resources and shall be owned by the IT system administrator.
    • The admin can share instance offerings, disk offerings, networks, images, and other cloud resources with sub-accounts or revoke the resources from sub-accounts. Sub-accounts can only manage resources to which they are granted access.
    • The admin can modify resource quotas granted to a sub-account based on different business scenarios.
    • After the admin created a VXLAN pool, sub-accounts can create VXLAN networks based on the VXLAN pool.
    • Changing the owner of a VM instance will change the owner properties of the EIPs associated with the VM instance.
  • Sub-account:
    • Sub-accounts can be categorized into local sub-accounts and SSO sub-accounts:
      • A local sub-account is created by the admin. An SSO sub-account is synced from an SSO authentication server.
        • SSO authentication: The SSO authentication service, powered by the Cloud, supports seamless access to SSO authentication systems. Through the service, related users can directly login to the Cloud and manage cloud resources. Currently, OIDC servers can be added.
          • OIDC server: An SSO authentication server that applies the OIDC protocol. It authenticates and authorizes SSO users to log into the Cloud without password and syncs user information to the Cloud based on the mapping rule.
      • A sub-account has management permissions on VM instances, images, volumes, and security groups created under the sub-account. A sub-account can perform read operations on resources shared by the admin, but cannot delete the resources.
      • Deleting a sub-account will delete all resources created by the sub-account, such as VM instances, volumes, and images.
      • The names of sub-accounts must be unique.
      • Resource quotas that the admin shares with a sub-account is displayed on the homepage of the sub-account.
      • Before a sub-account can create a VM instance, the admin must share an instance offering, disk offering, network, and other required resources with the sub-account. Otherwise, a VM instance cannot be created.
      • A sub-account can use an image that it adds to the Cloud or use an image shared by the admin.
  • Quota:

    Resource quotas that the admin shares with a sub-account specify the maximum resources that the sub-account can manage, including computing resource quotas, storage resource quotas, network resource quotas, and other resource quotas.

    The admin uses the preceding resource quota settings to manage the maximum resources granted to sub-accounts. If a resource is deleted but not expunged, the resource still occupies storage space of primary storage and volumes.

SSO Rename

Starting form ZStack Cloud 5.1.8, Third-party authentication is renamed to Single Sign-On (SSO). The following table describes some of the common term changes that have been updated throughout this guide as a result of the rename.
Legacy Term Current Term
Third-Party Authentication Single Sign On or SSO
Third-Party Authentication Server SSO Server
Third-Party Authentication System SSO System or SSO Authentication System
Third-Party User SSO User
Third-Party Sub-Account SSO Sub-Account
Third-Party Attribute SSO Attribute

Create a Local Sub-Account

On the main menu of ZStack Cloud, choose Settings > Sub-Account Setting > Sub-Account Management. On the Sub-Account page, click Create Sub-Account. Then, the Create Sub-Account page is displayed.

On the displayed page, set the following parameters:
  • Name: Enter a name for the local sub-account.
  • Description: Optional. Enter a description for the local sub-account.
  • Password: Enter a password for the local sub-account.
  • Confirm Password: Confirm the local sub-account password.
  • Pricing List: Optional. Select a pricing list. If left blank, the default pricing list is used.
Figure 1. Create Local Sub-account






Archives

Download Document Archives

Back to Top

Download

Already filled the basic info?Click here.

Enter at least 2 characters.
Invalid mobile number.
Enter at least 4 characters.
Invalid email address.
Wrong code. Try again. Send Code Resend Code (60s)

An email with a verification code will be sent to you. Make sure the address you provided is valid and correct.

同意 不同意

I have read and concur with the Site TermsPrivacy PolicyRules and Conventions on User Management of ZStack Cloud

Download

Not filled the basic info yet? Click here.

Invalid email address or mobile number.
同意 不同意

I have read and concur with the Site TermsPrivacy PolicyRules and Conventions on User Management of ZStack Cloud

Email Us

contact@zstack.io
ZStack Training and Certification
Enter at least 2 characters.
Invalid mobile number.
Enter at least 4 characters.
Invalid email address.
Wrong code. Try again. Send Code Resend Code (60s)

同意 不同意

I have read and concur with the Site TermsPrivacy PolicyRules and Conventions on User Management of ZStack Cloud

Email Us

contact@zstack.io
Request Trial
Enter at least 2 characters.
Invalid mobile number.
Enter at least 4 characters.
Invalid email address.
Wrong code. Try again. Send Code Resend Code (60s)

同意 不同意

I have read and concur with the Site TermsPrivacy PolicyRules and Conventions on User Management of ZStack Cloud

Email Us

contact@zstack.io

The download link is sent to your email address.

If you don't see it, check your spam folder, subscription folder, or AD folder. After receiving the email, click the URL to download the documentation.

The download link is sent to your email address.

If you don't see it, check your spam folder, subscription folder, or AD folder.
Or click on the URL below. (For Internet Explorer, right-click the URL and save it.)

Thank you for using ZStack products and services.

Submit successfully.

We'll connect soon.

Thank you for using ZStack products and services.