Skip to content

Network Sharing

By default, a private network is only visible to the project that owns it. Network sharing uses OpenStack RBAC policies to grant another project access to one of your private networks: the owning project keeps full control, while the target project can connect instances and routers to the shared network.

Typical use cases are a service project exposing a backend network to its clients, or a platform project sharing a common infrastructure network across several projects.

Warning

Sharing a network grants layer 2 access to the target project, which can take control of the traffic flowing through it. Only share networks with projects you trust — see Trust and traffic control.

Networks and Subnets Quotas

How it works

  •   Owner project


    The project that creates and owns the network and its subnets. It grants and revokes access at any time.

  •   Target project


    The project that receives access. It can connect instances and routers, but does not manage the network itself.

  •   RBAC policy


    The object binding the network to the target project with the action access_as_shared. One policy per target project.

  •   Quota


    The number of RBAC policies is limited by the rbac_policies quota (see Quotas).

graph LR
    A["Owner project<br>PCP-XXXXXXX"] -->|"owns"| B["shared-net<br>10.20.0.0/24"]
    A -->|"RBAC policy<br>access_as_shared"| C["Target project<br>PCP-YYYYYYY"]
    C -->|"ports, instances, router"| B

Example: share a network with another project

Prerequisites

  • The OpenStack CLI is installed and authenticated on the owning project.
  • The OpenStack ID (UUID) of the target project is known (see step 1).
  • The private network to share exists (see Create Networks and Subnets).

1. Get the target project ID

The target project must communicate its OpenStack ID. From a CLI session authenticated on the target project:

on the target project
openstack token issue -f value -c project_id
8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a

2. Create the network to share

On the owning project, create the network and its subnet as usual:

network and subnet
openstack network create shared-net
openstack subnet create --network shared-net --subnet-range 10.20.0.0/24 shared-subnet

3. Share the network

share the network
openstack network rbac create \
  --action access_as_shared \
  --type network \
  --target-project 8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a \
  shared-net
output
+-------------------+--------------------------------------+
| Field             | Value                                |
+-------------------+--------------------------------------+
| action            | access_as_shared                     |
| id                | d4e5f6a7-8901-4bcd-ae23-456789abcdef |
| object_id         | 2996c18e-babe-4012-b509-cdc9bd51d737 |
| object_type       | network                              |
| project_id        | ac4fafd60021431585bbb23470119557     |
| target_project_id | 8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a |
+-------------------+--------------------------------------+

Note

If your projects are not part of the default domain, specify the target project domain with --target-project-domain <domain>.

The same mechanism can share security groups, with --type security_group instead of --type network.

4. Verify the sharing

On the owning project, list the RBAC policies:

on the owning project
taylor@laptop:~$ openstack network rbac list
+--------------------------------------+------------------+--------------------------------------+------------------+--------------------------------------+--------------------------------------+
| ID                                   | Object Type      | Object ID                            | Action           | Project ID                           | Target Project ID                    |
+--------------------------------------+------------------+--------------------------------------+------------------+--------------------------------------+--------------------------------------+
| d4e5f6a7-8901-4bcd-ae23-456789abcdef | network          | 2996c18e-babe-4012-b509-cdc9bd51d737 | access_as_shared | ac4fafd60021431585bbb23470119557     | 8c1f4a2e-93b7-4a10-8f5d-21e6b0c9d47a |
+--------------------------------------+------------------+--------------------------------------+------------------+--------------------------------------+--------------------------------------+

On the target project, the network is now visible and usable:

on the target project
taylor@laptop:~$ openstack network list
+--------------------------------------+------------+----------------------------------------------------------------------------+
| ID                                   | Name       | Subnets                                                                    |
+--------------------------------------+------------+----------------------------------------------------------------------------+
| 2996c18e-babe-4012-b509-cdc9bd51d737 | shared-net | 6a29caa4-163b-4a63-9422-a88074389113                                       |
+--------------------------------------+------------+----------------------------------------------------------------------------+

5. Use the shared network

From the target project, the shared network is used like any other network: boot instances on it, or attach the subnet to one of its routers to get external connectivity through its own gateway:

on the target project
openstack server create \
  --image "Debian 13 trixie" \
  --flavor a2-ram4-disk80-perf1 \
  --key-name my-keypair \
  --network shared-net \
  client-vm

Note

Instances on the shared network get their IP addresses from the DHCP service of the owning project's subnet. Security groups, on the other hand, are applied at port level and are chosen by the target project.

6. Revoke the sharing

Retrieve the policy ID with openstack network rbac list, then delete it:

revoke access
openstack network rbac delete d4e5f6a7-8901-4bcd-ae23-456789abcdef

Warning

The RBAC policy can only be deleted once the target project has removed all its resources (ports, routers) from the shared network. The target project loses access as soon as the policy is deleted.

Trust and traffic control

Sharing a network is a trust decision at layer 2. The target project owns the ports it creates on the shared network and can take control of the traffic flowing through it:

  • it can disable port security on its own ports (--disable-port-security) or widen it with --allowed-address-pairs;
  • with port security disabled, it can spawn a port claiming the gateway address of the shared subnet (when it is not already allocated to a router) and answer ARP requests as the default gateway;
  • that instance then acts as a man-in-the-middle: it can intercept or alter the traffic of every instance connected to the shared network, including those of the owning project, or simply disrupt connectivity for all projects using the network;
  • it can also run a rogue DHCP server on the shared network and hand out malicious network configurations.

Limit the exposure

  • Share only with projects of your own organization, and revoke the RBAC policy as soon as the sharing is no longer needed.
  • Attaching the owning project's router to the subnet prevents the target project from claiming the gateway address with a port, but does not prevent ARP impersonation from a port with port security disabled: do not rely on it as a protection.
  • Audit the ports of the shared network from the owning project: openstack port list --network shared-net --long lists every connected port, including the ones created by the target project.
  • Prefer encrypted protocols (SSH, TLS, VPN) for sensitive traffic crossing the shared network.
  •   Networks and Subnets


    Create the private networks and subnets that can then be shared with other projects.

  •   Port Trunking


    Connect a single instance interface to several private networks using VLAN-tagged subports.

  •   Security Groups


    Firewall rules applied at port level, chosen by each project on the shared network.

  •   Quotas


    The number of RBAC policies is covered by the rbac_policies quota of your pack.