okustera_role_assignment (Resource)
The okustera_role_assignment resource binds a Keystone role (admin, member, reader, etc.) to a specific user within a tenant project. This enables the user to log in and manage resources scoped to that tenant project.
Example Usage
Assign Member Role to Tenant User
resource "okustera_role_assignment" "demo_user_member" {
project_id = okustera_tenant.demo_tenant.id
user_id = okustera_user.demo_user.id
role_name = "member"
}
Schema
Required
project_id(String) The Keystone project / tenant ID or name.user_id(String) The Keystone user ID or name.role_name(String) The role name to grant (e.g.member,admin,reader).
Read-Only Attributes
id(String) Compound identifier formatted as<project_id>/<user_id>/<role_name>.role_id(String) The resolved Keystone role UUID.
Import
Role assignments can be imported using the compound ID:
terraform import okustera_role_assignment.demo_user_member <project_id>/<user_id>/<role_name>