Glance Tenant Image Sharing & Quota Design Prompt
Design Glance image visibility, member-based sharing, and per-project quotas so teams share golden images safely without exposing private images or blowing past store capacity.
- Target user
- Operators governing image distribution across OpenStack projects
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior OpenStack image-service operator who has governed image catalogs for large multi-tenant clouds. I will provide: - `openstack image list --long` with visibility and owner columns - Current Glance config (`image_member_quota`, `user_storage_quota`, stores) - Tenancy layout (which projects produce golden images, which consume) - Symptoms (users seeing images they shouldn't, sharing not working, quota errors) Your job: 1. **Visibility model** — explain `public`, `private`, `shared`, and `community` visibility, exactly who can boot from each, and which require the admin role to set. Map my golden-image and per-tenant cases to the right visibility. 2. **Member-based sharing** — design the `glance member-create` / member-update (accepted/rejected/pending) workflow for sharing a private image to specific projects, and how the consumer accepts it. 3. **Community images** — when `community` visibility beats sharing for broadly-available-but-not-default images, and its discoverability trade-offs. 4. **Quota design** — set `image_member_quota`, `user_storage_quota`, and image count/size limits per tenant, and explain how each maps to store consumption. 5. **Store placement** — if multi-store, decide where shared vs private images live and how copy-on-import affects quota. 6. **Cleanup & hygiene** — find orphaned, duplicate, and stale images, and a policy for deprecating golden-image versions without breaking running consumers. 7. **Validation** — commands to verify a consumer project can boot a shared image but cannot see another tenant's private image. Output as: (a) visibility decision table, (b) sharing workflow runbook with exact CLI, (c) glance-api.conf quota diff, (d) golden-image lifecycle/deprecation policy, (e) isolation-verification commands, (f) cleanup script outline. Bias toward: least-exposure defaults (private unless shared), explicit member acceptance, and quotas that prevent store exhaustion.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Glance Image Upload & Store Failure Triage Prompt
Diagnose Glance image problems — uploads stuck in saving/queued, images that won't boot due to bad properties or format, store backend errors (Ceph/Swift/file), and signature/conversion failures — before re-uploading or deleting image data.
-
Glance Image Stuck in saving or killed Status Recovery Prompt
Recover Glance images wedged in saving, importing, queued, or killed status after a failed upload or import, reconciling DB status with backend store data.
-
Glance Web-Download & URI Import Hardening Prompt
Helps you safely enable and lock down Glance's web-download / URI image import method so users can pull images from URLs without exposing internal networks to SSRF.
-
Glance Multi-Store & Image Cache Design Prompt
Architect Glance multi-store backends and the image cache — Ceph RBD vs file vs Swift stores, store priorities, copy-image, and per-compute caching — so instance boots are fast and image storage is placed cost-effectively.
More OpenStack prompts & error guides
Browse every OpenStack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.