Administer > Permissions reference > OS Provisioning permissions

OS Provisioning permissions

This section describes the permissions required for OS provisioning. For security administrators, the following table answers this question: To perform a particular action, what permissions does a user need?

In the following table, the Server Permission column is for the servers referenced by the OS sequence or installation profile. Server permissions are specified by the Customer, Facility, and Device Groups permissions in the SA Client. To create and save an OS sequence in a folder, you will need write permissions to the folder.

OS Provisioning permissions required for user actions

User Action

Action Permission

Server Permission (Customer, Facility, Device Group)

Folder Permission

OS Build Plan

 

Create OS Build Plan

Manage OS Build Plan: Read & Write

None

Write

View OS Build Plan

Manage OS Build Plan: Read

None

Read

Edit OS Build Plan

Manage OS Build Plan: Read & Write

None

Write

Delete OS Build Plan

Manage OS Build Plan: Read & Write

None

Write

Add Device Group to OS Build Plan

Any of the permission combinations below is valid:

1) Manage Servers and Groups + Manage OS Build Plan: Read & Write, or

2) Manage Public Device Group (in Client Features tab, Servers section) + Manage OS Build Plan: Read & Write, or

3) Manage Public Device Groups (SA Client) (from Others tab, Servers and Device Group Permission section) + Manage OS Build Plan: Read & Write

None

Folder containing the OS Build Plan: Write

Add OGFS Script to OS Build Plan

Manage OGFS Script: Read + Manage OS Build Plan: Read & Write

None

Folder containing the OGFS Script: Read + Folder containing the OS Build Plan: Write

Add Server Script to OS Build Plan

Manage Server Script: Read + Manage OS Build Plan: Read & Write

None

Folder containing the Server Script: Read + Folder containing the OS Build Plan: Write

Add ZIP Package to OS Build Plan

Manage Package: Read + Manage OS Build Plan: Read & Write

None

Folder containing the package: Read + Folder containing the OS Build Plan: Write

Attach Software Policy to OS Build Plan

Manage Software Policy: Read + Manage OS Build Plan: Read & Write

None

Folder containing the Software Policy: Read + Folder containing the OS Build Plan: Write

Attach Windows Patch Policy to OS Build Plan

Manage Windows Patch: Policy + Manage OS Build Plan: Read & Write

None

Folder containing the OS Build Plan: Write

Run OS Build Plan (from server or from OS Build Plan node)

Managed Servers and Groups + Manage OS Build Plan: Allow Execute OS Build Plan: Yes

Read & Write

Folder containing the OS Build Plan: Execute

Run OS Build Plan (for VMware ESXi 4.1)

Manage Servers and Groups + Manage OS Build Plan: Read + Allow Execute OS Build Plan: Yes + Allow Manage Server +
View Virtual Servers +
Manage Virtual Servers

Read & Write

Folder (/Opsware
/Tools/OS Provisioning
) contains the Run OS Build Plan web extension: Execute + Folder containing the OS Build Plan: Execute + List and Execute folder permission on /Opsware/Tools/Virtualization Programs/Hypervisor Scanner folder

OS Sequence

 

Create OS Sequence

Manage OS Sequence: Read & Write + Operating Systems + Wizard: Prepare OS

  • To create an OS Sequence using an OS Installation Profile that is assigned to a customer, a user must have at least Read permission to the customer
  • To create an OS Sequence using a Customer Independent OS Installation Profile, no Customer permission is required.

Write

View OS Sequence

Manage OS Sequence:
Read

None

Read

Edit OS Sequence

Manage OS Sequence:
Read & Write

None

Write

Delete OS Sequence

Manage OS Sequence:
Read & Write

None

Write

Run OS Sequence

(From server or from OS sequences)

Manage OS Sequence:
Read

and

Allow Execute OS Sequence: Yes

Read & Write

Read

View unprovisioned servers

SA Client permission: Server Pool

Read

N/A

Attach Software Policy

Manage Software Policy: Read + Manage OS Sequence: Read & Write

NA

Folder containing the Software Policy: Read + Folder containing the OS Sequence: Write

Attach Windows Patch Policy

Manage Windows Patch: Policy + Manage OS Sequence: Read & Write

NA

Folder containing the OS Sequence: Write

Attach Solaris Patch Policy

Manage Software Policy: Read + Manage OS Sequence: Read & Write

NA

Folder containing the Solaris Patch Policy: Read + Folder containing the OS Sequence: Write

OS Installation Profile

Create, edit, delete OS installation profile

Operating System + Wizard: Prepare OS

Note: To create an OS Sequence using an OS Installation Profile that is assigned to a customer, the customer must have read & write permission.

Note: To create an OS Sequence using a Customer Independent OS Installation Profile, no Customer permission is required.

N/A

Unprovisioned Server List

View servers in the unprovisioned server list

Server Pool

N/A

N/A

Manage Boot Clients

Execute Managed Boot Clients Web Application

Allow Configuration of Network Booting + Managed Server and Groups
+ Manage Customers
+ Server Pool

Read/Write to the Facility and Customer
+ Read/Write to customer Not Assigned

List and Execute on the /Opsware
/Tools/OS Provisioning/Manage Boot Clients
folder

The User Actions Allowed in the SA Client by OS Provisioning Permissions table lists the actions that users can perform for each OS Provisioning permission. The User Actions Allowed in the SA Client by OS Provisioning Permissions table has the same data as the OS Provisioning permissions required for user actions table, but is sorted by action permission.

For security administrators, the User Actions Allowed in the SA Client by OS Provisioning Permissions table answers this question: If a user is granted a particular action permission, what actions can the user perform?

User Actions Allowed in the SA Client by OS Provisioning Permissions

Action Permission

User Action

Server Permission (Customer, Facility, Device Group)

Folder

Manage OS Sequence: Read

View OS sequence

Read

Read

Manage OS Sequence: Read & Write + Operating System + Wizard: Prepare OS

Create OS sequence

Read

Write

Allow Execute OS Sequence: Yes

Run OS sequence

Write

Read

Manage OS Sequence: Read
Allow execute OS Sequence: Yes

Run OS sequence

Write

Read

Manage OS Sequence: Read
Allow Execute OS Sequence: No

View OS sequence

Read

Read

Manage OS Sequence: Write
Allow Execute OS Sequence: Yes

Run OS sequence

Edit OS sequence

Write

Write

Manage OS Sequence: Write
Allow Execute OS Sequence: No

Edit OS sequence

Read

Write

Operating System+
Wizard: Prepare OS

Create, edit, delete OS installation profile

Read & Write,
N/A,
N/A

N/A

Server Pool

View servers in the unprovisioned server list

Read

N/A

Manage boot clients permissions

The following section describes the permissions required to use the Manage Boot Clients (MBC) Utility for OS Provisioning.

Manage boot client utility permissions

Action Permission

User Action

Server Permission (Customer, Facility, Device Group)

Folder

Allow Execute OS Build Plan

Run OS Build Plan

Write

Read

Allow Execute OS Sequence

Run OS Sequence

Write

Read

Manage Server and Groups

Manage Server and Groups

Write

Read

Manage Customers

Create, edit Customers

Write

Read

Server Pool

Access Server Pool

Write

Read

Read & Write permission to customer Not Assigned

Access to servers assigned to customer Not Assigned

Write

Read

Allow Configuration of Network Booting

Configuration of Network Booting

Write

Read