vSphere权限管理模型
理解vpx user用户的作用
By default, when ESX/ESXi is installed, the only user that exists is the root user, and
root has full administrative permissions to the entire server. This default set of
permissions changes when an ESX/ESXi host is managed by vCenter Server. The
process of adding a host to vCenter Server adds an agent (the vCenter Server
Agent) and an additional Service Console account called vpxuser. The vpxuser
account has a 32-character, complex, randomly generated password that is also granted
membership in the Administrator role on an ESX/ESXi host. This assignment enables
the vCenter Server service to carry out tasks on the ESX/ESXi hosts in the inventory.
vCenter管理和维护权限的优势
1.中心的权限管理
2.可以利用域用户
3.可以利用数据中心,文件夹,资源池来指派权限
4. VM和Template通过部门来组织,Host和Cluster通过地理位置来组织
Step1: 可以在vcenter 中创建新的角色
Step2:关联权限与用户组
再用vmoperator用户登入进去只能看到一个esxi host