Share Tenancy with Tenant#

Note

Tenants, tenancies, and other features are available if you have paid for multi-tenant support. Contact Penguin Computing to learn more.

When a tenancy is fully deployed and running, the root account on the ICE ClusterWare ™ head node is a Full Admin and that account is accessible to superadministrators. With that account, you can complete any final configuration and share the tenancy details with the tenant.

Tenancy Administrator Accounts#

Use the Managed Tenants role to grant permissions to the tenancy administrator user. A new tenancy already has a user account with this role assigned. The user is associated with the SSH key provided in the Terraform file used for tenancy creation. A tenancy can have multiple users with the Managed Tenant role.

Users with the Managed Tenants role are able to complete many actions within the ClusterWare software in their tenancy:

  • Power control for nodes

  • Create and update attributes

  • Create and update attribute groups

  • Read reserved attributes

  • Create and update administrator users with the Managed Tenant role or a lesser role

  • Read other primitive data, such as node status, dynamic groups, and so on

See Role-Based Access Controls and User Roles for details.

Either a superadministrator or a tenancy administrator with the Managed Tenants role can create additional Managed Tenants users within a tenancy. For example:

cw-adminctl create name=<name> roles=ManagedTenant

Grafana User Accounts#

A set of Grafana user accounts are created when the ClusterWare software is installed on the tenancy head node. The account credentials are stored in the /opt/scyld/clusterware-grafana/lib/grafana-users file, which is only accessible by the superadministrator. See Grafana User Accounts for details about sharing credentials with tenancy administrators.