Network Sharing
By default, a private network is only visible to the project that owns it. Network sharing uses OpenStack RBAC policies to grant another project access to one of your private networks: the owning project keeps full control, while the target project can connect instances and routers to the shared network.
Typical use cases are a service project exposing a backend network to its clients, or a platform project sharing a common infrastructure network across several projects.
Warning
Sharing a network grants layer 2 access to the target project, which can take control of the traffic flowing through it. Only share networks with projects you trust — see Trust and traffic control.
How it works
-
Owner project
The project that creates and owns the network and its subnets. It grants and revokes access at any time.
-
Target project
The project that receives access. It can connect instances and routers, but does not manage the network itself.
-
RBAC policy
The object binding the network to the target project with the action
access_as_shared. One policy per target project. -
Quota
The number of RBAC policies is limited by the
rbac_policiesquota (see Quotas).
graph LR
A["Owner project<br>PCP-XXXXXXX"] -->|"owns"| B["shared-net<br>10.20.0.0/24"]
A -->|"RBAC policy<br>access_as_shared"| C["Target project<br>PCP-YYYYYYY"]
C -->|"ports, instances, router"| B
Example: share a network with another project
Prerequisites
- The OpenStack CLI is installed and authenticated on the owning project.
- The OpenStack ID (UUID) of the target project is known (see step 1).
- The private network to share exists (see Create Networks and Subnets).
1. Get the target project ID
The target project must communicate its OpenStack ID. From a CLI session authenticated on the target project:
openstack token issue -f value -c project_id
8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a
2. Create the network to share
On the owning project, create the network and its subnet as usual:
openstack network create shared-net
openstack subnet create --network shared-net --subnet-range 10.20.0.0/24 shared-subnet
3. Share the network
openstack network rbac create \
--action access_as_shared \
--type network \
--target-project 8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a \
shared-net
+-------------------+--------------------------------------+
| Field | Value |
+-------------------+--------------------------------------+
| action | access_as_shared |
| id | d4e5f6a7-8901-4bcd-ae23-456789abcdef |
| object_id | 2996c18e-babe-4012-b509-cdc9bd51d737 |
| object_type | network |
| project_id | ac4fafd60021431585bbb23470119557 |
| target_project_id | 8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a |
+-------------------+--------------------------------------+
Note
If your projects are not part of the default domain, specify the target project domain with --target-project-domain <domain>.
The same mechanism can share security groups, with --type security_group instead of --type network.
4. Verify the sharing
On the owning project, list the RBAC policies:
taylor@laptop:~$ openstack network rbac list
+--------------------------------------+------------------+--------------------------------------+------------------+--------------------------------------+--------------------------------------+
| ID | Object Type | Object ID | Action | Project ID | Target Project ID |
+--------------------------------------+------------------+--------------------------------------+------------------+--------------------------------------+--------------------------------------+
| d4e5f6a7-8901-4bcd-ae23-456789abcdef | network | 2996c18e-babe-4012-b509-cdc9bd51d737 | access_as_shared | ac4fafd60021431585bbb23470119557 | 8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a |
+--------------------------------------+------------------+--------------------------------------+------------------+--------------------------------------+--------------------------------------+
On the target project, the network is now visible and usable:
taylor@laptop:~$ openstack network list
+--------------------------------------+------------+----------------------------------------------------------------------------+
| ID | Name | Subnets |
+--------------------------------------+------------+----------------------------------------------------------------------------+
| 2996c18e-babe-4012-b509-cdc9bd51d737 | shared-net | 6a29caa4-163b-4a63-9422-a88074389113 |
+--------------------------------------+------------+----------------------------------------------------------------------------+
5. Use the shared network
From the target project, the shared network is used like any other network: boot instances on it, or attach the subnet to one of its routers to get external connectivity through its own gateway:
openstack server create \
--image "Debian 13 trixie" \
--flavor a2-ram4-disk80-perf1 \
--key-name my-keypair \
--network shared-net \
client-vm
Note
Instances on the shared network get their IP addresses from the DHCP service of the owning project's subnet. Security groups, on the other hand, are applied at port level and are chosen by the target project.
6. Revoke the sharing
Retrieve the policy ID with openstack network rbac list, then delete it:
openstack network rbac delete d4e5f6a7-8901-4bcd-ae23-456789abcdef
Warning
The RBAC policy can only be deleted once the target project has removed all its resources (ports, routers) from the shared network. The target project loses access as soon as the policy is deleted.
Trust and traffic control
Sharing a network is a trust decision at layer 2. The target project owns the ports it creates on the shared network and can take control of the traffic flowing through it:
- it can disable port security on its own ports (
--disable-port-security) or widen it with--allowed-address-pairs; - with port security disabled, it can spawn a port claiming the gateway address of the shared subnet (when it is not already allocated to a router) and answer ARP requests as the default gateway;
- that instance then acts as a man-in-the-middle: it can intercept or alter the traffic of every instance connected to the shared network, including those of the owning project, or simply disrupt connectivity for all projects using the network;
- it can also run a rogue DHCP server on the shared network and hand out malicious network configurations.
Limit the exposure
- Share only with projects of your own organization, and revoke the RBAC policy as soon as the sharing is no longer needed.
- Attaching the owning project's router to the subnet prevents the target project from claiming the gateway address with a port, but does not prevent ARP impersonation from a port with port security disabled: do not rely on it as a protection.
- Audit the ports of the shared network from the owning project:
openstack port list --network shared-net --longlists every connected port, including the ones created by the target project. - Prefer encrypted protocols (SSH, TLS, VPN) for sensitive traffic crossing the shared network.
Related resources
-
Create the private networks and subnets that can then be shared with other projects.
-
Connect a single instance interface to several private networks using VLAN-tagged subports.
-
Firewall rules applied at port level, chosen by each project on the shared network.
-
The number of RBAC policies is covered by the
rbac_policiesquota of your pack.