vSphere权限管理模型

clip_p_w_picpath002

理解vpx user用户的作用

By default, when ESX/ESXi is installed, the only user that exists is the root user, and

root has full administrative permissions to the entire server. This default set of

permissions changes when an ESX/ESXi host is managed by vCenter Server. The

process of adding a host to vCenter Server adds an agent (the vCenter Server

Agent) and an additional Service Console account called vpxuser. The vpxuser

account has a 32-character, complex, randomly generated password that is also granted

membership in the Administrator role on an ESX/ESXi host. This assignment enables

the vCenter Server service to carry out tasks on the ESX/ESXi hosts in the inventory.

vCenter管理和维护权限的优势

1.中心的权限管理

2.可以利用域用户

3.可以利用数据中心,文件夹,资源池来指派权限

4. VMTemplate通过部门来组织,HostCluster通过地理位置来组织

Step1: 可以在vcenter 中创建新的角色

clip_p_w_picpath004

Step2:关联权限与用户组

clip_p_w_picpath006

clip_p_w_picpath008

再用vmoperator用户登入进去只能看到一个esxi host

clip_p_w_picpath010