<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cinder Mitaka RH OSP9 insufficient privileges qos-policy-group in OpenStack Discussions</title>
    <link>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127837#M317</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cinder and Glance are working ok with Netapp FAS8020 ontap 8.3 (NFS). We have a copy offload license and this is also working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the volume log in Cinder contains permissions errors&amp;nbsp; as follows -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;ERROR cinder.volume.drivers.netapp.dataontap.performance.perf_cmode NaApiError: NetApp API failed. Reason - 13003:Insufficient privileges: user 'openstack' does not have read access to this resource&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and on the netapp command log -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;[kern_command-history:info:909] ontapi :: [ip address] :: openstack :: &amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.31"&amp;gt;&amp;lt;qos-policy-group-delete-iter&amp;gt;&amp;lt;max-records&amp;gt;3500&amp;lt;/max-records&amp;gt;&amp;lt;query&amp;gt;&amp;lt;qos-policy-group-info&amp;gt;&amp;lt;policy-group&amp;gt;deleted_cinder_*&amp;lt;/policy-group&amp;gt;&amp;lt;vserver&amp;gt;[vserver_name]&amp;lt;/vserver&amp;gt;&amp;lt;/qos-policy-group-info&amp;gt;&amp;lt;/query&amp;gt;&amp;lt;return-success-list&amp;gt;false&amp;lt;/return-success-list&amp;gt;&amp;lt;return-failure-list&amp;gt;false&amp;lt;/return-failure-list&amp;gt;&amp;lt;continue-on-failure&amp;gt;true&amp;lt;/continue-on-failure&amp;gt;&amp;lt;/qos-policy-group-delete-iter&amp;gt;&amp;lt;/netapp&amp;gt; :: Pending&lt;BR /&gt;&amp;nbsp;[kern_command-history:info:909] ontapi :: [ip address] :: openstack :: Insufficient privileges: user 'openstack' does not have write access to this resource :: ONTAPI :: Error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what may be causing this error.?&lt;/P&gt;&lt;P&gt;The NetApp role was set up as per NetApp documentation here -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://netapp.github.io/openstack-deploy-ops-guide/mitaka/content/cinder.fas.configuration.html#cinder.cdot.account_permissions" target="_blank"&gt;http://netapp.github.io/openstack-deploy-ops-guide/mitaka/content/cinder.fas.configuration.html#cinder.cdot.account_permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user is a cluster level user&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 15:29:08 GMT</pubDate>
    <dc:creator>openstack1</dc:creator>
    <dc:date>2025-06-04T15:29:08Z</dc:date>
    <item>
      <title>Cinder Mitaka RH OSP9 insufficient privileges qos-policy-group</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127837#M317</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cinder and Glance are working ok with Netapp FAS8020 ontap 8.3 (NFS). We have a copy offload license and this is also working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the volume log in Cinder contains permissions errors&amp;nbsp; as follows -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;ERROR cinder.volume.drivers.netapp.dataontap.performance.perf_cmode NaApiError: NetApp API failed. Reason - 13003:Insufficient privileges: user 'openstack' does not have read access to this resource&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and on the netapp command log -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;[kern_command-history:info:909] ontapi :: [ip address] :: openstack :: &amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.31"&amp;gt;&amp;lt;qos-policy-group-delete-iter&amp;gt;&amp;lt;max-records&amp;gt;3500&amp;lt;/max-records&amp;gt;&amp;lt;query&amp;gt;&amp;lt;qos-policy-group-info&amp;gt;&amp;lt;policy-group&amp;gt;deleted_cinder_*&amp;lt;/policy-group&amp;gt;&amp;lt;vserver&amp;gt;[vserver_name]&amp;lt;/vserver&amp;gt;&amp;lt;/qos-policy-group-info&amp;gt;&amp;lt;/query&amp;gt;&amp;lt;return-success-list&amp;gt;false&amp;lt;/return-success-list&amp;gt;&amp;lt;return-failure-list&amp;gt;false&amp;lt;/return-failure-list&amp;gt;&amp;lt;continue-on-failure&amp;gt;true&amp;lt;/continue-on-failure&amp;gt;&amp;lt;/qos-policy-group-delete-iter&amp;gt;&amp;lt;/netapp&amp;gt; :: Pending&lt;BR /&gt;&amp;nbsp;[kern_command-history:info:909] ontapi :: [ip address] :: openstack :: Insufficient privileges: user 'openstack' does not have write access to this resource :: ONTAPI :: Error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what may be causing this error.?&lt;/P&gt;&lt;P&gt;The NetApp role was set up as per NetApp documentation here -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://netapp.github.io/openstack-deploy-ops-guide/mitaka/content/cinder.fas.configuration.html#cinder.cdot.account_permissions" target="_blank"&gt;http://netapp.github.io/openstack-deploy-ops-guide/mitaka/content/cinder.fas.configuration.html#cinder.cdot.account_permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user is a cluster level user&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 15:29:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127837#M317</guid>
      <dc:creator>openstack1</dc:creator>
      <dc:date>2025-06-04T15:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cinder Mitaka RH OSP9 insufficient privileges qos-policy-group</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127872#M319</link>
      <description>&lt;P&gt;Might be handy to post a trial of creating/deleteing QOS from Clustershell using this user on involved vols and Vserver&amp;nbsp;and then we dig deeper into this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Bishoy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 14:32:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127872#M319</guid>
      <dc:creator>Bishoy</dc:creator>
      <dc:date>2017-02-08T14:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cinder Mitaka RH OSP9 insufficient privileges qos-policy-group</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127888#M322</link>
      <description>&lt;P&gt;In your &lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;cinder.conf&lt;/STRONG&gt;&lt;/FONT&gt;, do you have the value of&amp;nbsp;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;netapp_server_hostname&lt;/STRONG&gt;&lt;/FONT&gt; set as the IP address of&lt;EM&gt;&amp;nbsp;the&lt;STRONG&gt; cluster management LIF&lt;/STRONG&gt;?&amp;nbsp;&lt;/EM&gt;You're on the right track with respect to using the Cluster-scoped account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to reiterate, the "&lt;FONT face="courier new,courier"&gt;qos policy-group&lt;/FONT&gt;" command requires a Cluster-scoped account, and you need to ensure that you have&amp;nbsp;&lt;FONT face="courier new,courier"&gt;netapp_server_hostname&lt;/FONT&gt;&amp;nbsp;in your cinder.conf set as the IP address of the cluster management LIF.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 00:26:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127888#M322</guid>
      <dc:creator>SumitK</dc:creator>
      <dc:date>2017-02-09T00:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cinder Mitaka RH OSP9 insufficient privileges qos-policy-group</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127904#M324</link>
      <description>&lt;P&gt;Yes the cinder.conf correctly has the cluster management LIF ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A ticket has been opened with NetApp support. I will report back on any progress&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 13:17:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/127904#M324</guid>
      <dc:creator>openstack1</dc:creator>
      <dc:date>2017-02-09T13:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cinder Mitaka RH OSP9 insufficient privileges qos-policy-group</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/129532#M327</link>
      <description>&lt;P&gt;I have already addressed this with support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bugs.launchpad.net/cinder/+bug/1670879&amp;nbsp;" target="_blank"&gt;https://bugs.launchpad.net/cinder/+bug/1670879&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 03:07:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Cinder-Mitaka-RH-OSP9-insufficient-privileges-qos-policy-group/m-p/129532#M327</guid>
      <dc:creator>Bishoy</dc:creator>
      <dc:date>2017-03-29T03:07:47Z</dc:date>
    </item>
  </channel>
</rss>

