Manage projects
Projects in Bastionhost isolate O&M assets by organizational unit, ensuring that different teams can only access and manage assets within their authorized scope. Create projects and configure project authorization to achieve multi-tenant data isolation across assets, accounts, user groups, authorization rules, and control policies.
The project management feature is in limited release. If you have related requirements, join the DingTalk group (group ID: 33797269) to consult with product engineers.
Background information
A project is an asset isolation unit within Bastionhost. The following data belongs to a project: assets, asset accounts, asset groups, network domains, password change tasks, shared keys, O&M tasks, user groups, authorization rules, control policies, third-party resources, approval to-do items, and completed approval items.
Bastionhost has a built-in Default project with the following characteristics:
Its name cannot be modified and it cannot be deleted.
All administrators can manage data in the Default project.
Assets under member accounts that are not associated with a custom project, as well as assets under the Bastionhost instance owner account, can only be imported into the Default project.
In addition to the Default project, you can create custom projects. Custom projects can only be viewed and managed by project administrators designated in Project Authorization.
Quotas and limits
Item | Description |
Maximum number of projects | 50 (including the Default project) |
Member account association | A member account can only be associated with one project |
Default project | Its name cannot be modified, it cannot be deleted, and separate notification recipients cannot be configured |
Permission requirements
Before you perform the operations described in this topic, you must have Bastionhost administrator permissions (AliyunYundunBastionHostFullAccess). For more information about permissions, see Grant management permissions to a RAM user.
Create a project
A Default project is built in by default. You can create custom projects based on your business requirements. A maximum of 50 projects are supported, including the built-in Default project.
Log on to the Bastionhost console, find the target instance, and click Manage.
In the left-side navigation pane, choose System Settings > Project Management.
Click Create Project.
In the Create Project panel, configure the following parameters.
Parameter | Description |
Project Name | The name of the custom project. |
Remarks | The description of the project. |
Associate Member Account | Optional. After you associate member accounts, the project administrator can only pull assets from the associated member accounts when importing ECS, RDS, or PolarDB assets. A project can be associated with multiple member accounts, but a member account can only be associated with one project. |
Click OK to complete the project creation.
Manage projects
On the Project Management page, click the name of a target project to go to the project details page, where you can manage the basic information, asset scope, and notification recipients of the project.
Modify basic information
On the Project Management page, click the name of the target project.
On the Basic Information tab, modify the name and description of the project.
The name of the Default project cannot be modified.
Configure asset scope
Prerequisites:
You have completed Unified multi-account management.
You have created a custom project.
On the Project Management page, click the name of the target project.
Click the Asset Scope tab to manage the member accounts associated with this project.
After you associate member accounts, the administrator of this custom project can only pull assets from the associated member accounts when importing Alibaba Cloud assets (ECS, RDS, or PolarDB).
Configuration rules:
Assets under member accounts that are not associated with a custom project, as well as assets under the Bastionhost instance owner account, can only be imported into the Default project.
A member account can only be associated with one project.
Before you remove a member account from a project, you must first remove all assets that belong to this member account from the project. Otherwise, the member account cannot be removed.
Configure notification recipients
Prerequisite: On the System Settings > Notification page, you have enabled SMS or email notifications for relevant notification items.
On the Project Management page, click the name of the target project.
Click the Message Recipient tab to configure recipients for the following five notification categories:
Command alert notifications
O&M approval notifications
Shared key change reminders
Automation task notifications
Network domain alert notifications
Configuration rules:
If you configure recipients within a project, notifications triggered by assets in this project are sent to both the alert administrators configured on the System Settings > Notification page and the recipients configured here.
If no recipients are configured within a project, notifications are sent only to the alert administrators configured on the System Settings > Notification page.
The Default project does not support separate recipient configuration. Notifications triggered by assets in the Default project are sent only to the alert administrators configured on the System Settings > Notification page.
Delete a project
On the Project Management page, click Delete in the Actions column of the target project.
Deleting a project removes all data within the project, including assets, asset accounts, asset groups, network domains, password change tasks, shared keys, O&M tasks, user groups, authorization rules, and control policies. This operation is irreversible. Proceed with caution.
The Default project cannot be deleted.
Configure project authorization
Project authorization specifies the scope of projects that a project administrator can manage. For custom projects, only project administrators added in the project authorization settings can view and manage data within the project.
To manage data in a custom project, the following two conditions must be met:
The RAM role or RAM user has been granted the Bastionhost project administrator permissionAliyunYundunBastionHostProjectAdminAccess.
In the Project Authorization settings of Bastionhost, the RAM role or RAM user has been designated as a project administrator and the scope of manageable projects has been configured.
AliyunYundunBastionHostProjectAdminAccess is a Deny-type policy. If a user also needs Bastionhost administrator permissions, grant the user AliyunYundunBastionHostFullAccess only. Do not simultaneously grant AliyunYundunBastionHostProjectAdminAccess, as this will prevent the user from accessing modules such as System Settings in Bastionhost.
Create a project authorization
Log on to the Bastionhost console, find the target instance, and click Manage.
In the left-side navigation pane, choose System Settings > Project Management.
Click the Project Authorization tab, and then click Create Project Authorization.
Configure the following parameters.
Parameter | Description |
Project Administrator | Select a RAM role or RAM user as the project administrator. |
Asset Scope | Specify the scope of projects that the project administrator can manage. Valid values: All projects: The project administrator can manage data in all projects on the Bastionhost instance. Specified projects: The project administrator can only manage data in the Default project and the projects specified here. If no project is specified, the administrator can only manage data in the Default project. |
Click OK.
UI changes after enabling the project feature
After you enable the project feature, when you navigate to the Assets, User Groups, Authorization Rules, Control Policies, and Approval menu pages, a project switcher appears in the upper-left corner of the page. The page displays only data for the currently selected project. The operational procedures for these feature modules remain unchanged.