Keystone Hierarchical Project & Nested Quota Design Prompt
Helps you design a Keystone project hierarchy with nested quotas so business units self-manage sub-projects without exceeding a parent allocation.
- Target user
- Cloud platform and identity administrators
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior Keystone and quota administrator who designs hierarchical multi-tenancy for large private clouds. I will provide: - The org structure to model (domains, parent projects, sub-projects) - Which services need nested quota enforcement (Nova, Cinder, Neutron) - Current flat quotas and any over-allocation pain points - RBAC requirements (who can create sub-projects and set child quotas) Your job: 1. **Hierarchy model** — map domains → parent projects → sub-projects with `openstack project create --parent`, noting depth limits. 2. **Quota strategy** — define which services support nested/hierarchical quotas and where you must fall back to manual sub-allocation. 3. **Allocation math** — show how child quotas must sum within parent limits and how to leave headroom. 4. **RBAC** — assign roles so a BU admin can manage children but not exceed the parent envelope. 5. **Commands** — `openstack quota set` per project plus role assignments and verification queries. 6. **Drift detection** — a method to reconcile actual usage vs quota across the tree (`openstack quota show --usage`). 7. **Migration & back-out** — how to move existing projects under a parent and revert if enforcement breaks workflows. Output as: (a) a hierarchy + quota allocation table, (b) ordered CLI, (c) a reconciliation + rollback checklist. Test the hierarchy in a throwaway domain first; reparenting projects can disrupt quota accounting, so snapshot current quotas before changes.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Keystone Token & Auth Failure Triage Prompt
Diagnose Keystone authentication and authorization failures (401/403, expired Fernet tokens, broken role assignments, federation/LDAP lookup errors) by tracing the auth request through token validation, catalog, and policy enforcement.
-
Keystone Fernet to JWS Token Provider Migration Prompt
Plan a safe cutover from the Fernet token provider to JWS (asymmetric) tokens across a multi-node Keystone deployment without invalidating live sessions.
-
Keystone LDAP Identity Backend Debug Prompt
Diagnose why Keystone authentication against an external LDAP/Active Directory identity backend fails, returns wrong group memberships, or is slow, while keeping service accounts in the SQL backend.
-
Keystone Token Validation Latency Debug Prompt
Diagnose slow API calls cloud-wide caused by Keystone token validation latency, covering Fernet overhead, catalog size, caching misses, and auth_token middleware behavior.
More OpenStack prompts & error guides
Browse every OpenStack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.