solaris 11 zones (4) delegation example

Delegate zonemanagement of zone3 to user peter.

# zoneadm list -cv
ID NAME STATUS PATH BRAND IP
0 global running / solaris shared
2 zone3 running /rpool/zones/zone3 solaris excl

# zonecfg -z zone3
zonecfg:zone3> add admin
zonecfg:zone3:admin> set user=peter
zonecfg:zone3:admin> set auths=manage
zonecfg:zone3:admin> end
zonecfg:zone3> commit
zonecfg:zone3> exit

# su - peter
# pfexec bash
# zlogin zone3

[Connected to zone 'zone3' pts/7]
Oracle Corporation SunOS 5.11 11.0 August 2012
root@zone3:~# exit

# zoneadm -z zone3 halt

note: another way of setting authorizations
# usermod -P+"Zone Management" -A+solaris.zone.manage/zone1 peter
# usermod -A+solaris.zone.login/zone2 peter

note: use pfexec bash to test because bash is not RBAC aware.

This entry was posted in solaris. Bookmark the permalink.

Comments are closed.