Sub-account is a new concept introduced by ZStack Cloud for resource control, which is used to define and isolate resource owners.
Each sub-account can use, modify, share, and revoke its own resources, as well as use resources shared with it by other sub-accounts (Specifically, "use" stands for operations such as creating a VM instance or creating a volume). Sub-account is created and managed by the admin, is given the permission to manage the virtual resources it creates.
After installing ZStack Cloud, you need to log in to the Cloud through the admin to add and configure key resources following the wizard. Then you can create sub-accounts. By default, a sub-account has no access to key resources created by the admin, such as instance offerings, disk offerings, hosts, images, and networks. For the sub-account to create a VM instance, the admin needs to share with it the necessary resources including instance offerings and networks. A sub-account has the permissions to create, delete, and manage VM instances, images, volumes, security groups, user groups, and users.
Attribute | Admin | Sub-Account |
---|---|---|
Life Cycle | Always exists and cannot be deleted. | Created by the admin and can be deleted. |
Default Permission | Global super permission. | Partial permission. |
Resource Quota | Global use. | Quotas are managed by the admin. |
Available Resources | Global resources (except for user groups). | VM instances, images, volumes, security groups, user groups, and users. |
Sharable/Revokable Resources | Disk offerings, volume offerings, networks, and images. | Images shared by the admin. |
VM Instances Created by Other Accounts | Global view and control. | Cannot view or control resources of other accounts. |
Images Added by Other Accounts | Global view and control. |
|
Sharing/Revoking Method | Single account / Accounts in Batches / Global. |
|
Supported Operations | Global operations (except for creating and modifying permissions for common users). | All operations on the resources it creates, including VM instances, images, volumes, security groups, user groups, and users. |
Prerequisites for Creating a VM Instance | Configure the basic environment by the wizard. |
|
Consequences of Deletion | Cannot be deleted. | Once the sub-account is deleted, all resources owned by the sub-account are also deleted, including VM instances, images, volumes, security groups, user groups, and users. |
Naming | Uncustomizable. | Customizable. Account names must be unique. |
Back to Top
Email Us
contact@zstack.ioEmail Us
contact@zstack.ioEmail Us
contact@zstack.ioThe download link is sent to your email address.
If you don't see it, check your spam folder, subscription folder, or AD folder. After receiving the email, click the URL to download the documentation.Thank you for using ZStack products and services.
Submit successfully.
We'll connect soon.Thank you for using ZStack products and services.