public inbox for kvm@vger.kernel.org
 help / color / mirror / Atom feed
* restricting users to only power control of VMs
@ 2011-06-08 18:10 Iordan Iordanov
  2011-06-09  8:14 ` Avi Kivity
  0 siblings, 1 reply; 4+ messages in thread
From: Iordan Iordanov @ 2011-06-08 18:10 UTC (permalink / raw)
  To: kvm

Hi,

As the subject suggests, we are wondering whether there is any way to 
restrict certain classes of users from performing any action other than 
powering a VM up and down, and resetting it?

If this can't be done with KVM, does anybody have suggestions on how 
this can be accomplished? The only way I can think of is with a setuid 
binary that can only start VMs and send reset and shutdown commands to 
its monitor socket. However, this does seem hackish and can be insecure 
if it's not written perfectly.

Cheers,
Iordan

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2011-06-22  8:01 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-06-08 18:10 restricting users to only power control of VMs Iordan Iordanov
2011-06-09  8:14 ` Avi Kivity
2011-06-21 21:45   ` Iordan Iordanov
2011-06-22  8:00     ` Avi Kivity

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox