0
votes

Is it possible to scope Openstack CLI output for listing networks only for a single project. I have tried multiple options like --os-project-id, --os-project-name etc but it seems to list down all networks across multiple projects/tenants.

Currently, the command I am using is:

openstack network list --os-username XXX --os-password YYY --os-project-id ZZZ

Note: The credentials that I am using here are of an 'admin' account

Parameters set in the environment are :

OS_PROJECT_ID=XXX
OS_REGION_NAME=XXX
OS_TENANT_ID=XXX
OS_USER_DOMAIN_NAME=XXX
OS_PROJECT_NAME=XXX
OS_AUTH_VERSION=XXX
OS_IDENTITY_API_VERSION=XXX
OS_PASSWORD=XXX
OS_AUTH_URL=XXX
OS_USERNAME=XXX
OS_TENANT_NAME=XXX
OS_INTERFACE=XXX
OS_PROJECT_DOMAIN_NAME=XXX
3
can you run the command with --no-share option? - kuro
Can you check whether you have V3 support enabled for keystone? - kuro
Anyway, I think you get your information if the user has _member_ role instead of admin - kuro
@kuro Thanks for the suggestions. I tried using '--no-share' option but still get the same output. - akskap
@kuro How can I check if keystone supports v3 ? I already have OS_IDENTITY_API_VERSION=3 set in my environment variables - akskap

3 Answers

0
votes

May be your networks are shared by all tenants. If you only have a few networks you can verify with neutron net-show Network-Name and review the shared attribute

BTW I use the env variable OS_PROJECT_NAME to switch between projects

0
votes

Without any explicit filter specified in the parameters, Neutron's network API returns all networks that the user accessing the API has privileges to list. The recommended way to scope down the list of networks to a specific project is to explicitly specify that filter.

Via CLI, you can scope the list to a specific project "demo" using the following example:

openstack network list --project demo

You can see more filtering options via the help text:

openstack help network list
0
votes

Issues were caused by an older version of Openstack CLI v3.7.0

Using Openstack CLI version v3.13.0, I was able to solve my requirement. By default, with the domain admin account, the CLI still dumped the entire network list but with the --long flag, the 'project' field this time was populated and I could filter out the results for the specific project.

This was not the case with the previous CLI versions. Usage of '--long' flag had all the values of 'Project' as none.