User management

Global resources and local resources

Global resources are resources unique across regions.

Information managed by the user management function includes domains, groups, users, and roles.

Local resources are resources enclosed within each region.

Information managed by the user management function includes projects, tokens, trusts, and role assignments.

User management function for local use

The user management function for local use provides features for user authentication and reference, project creation, and other features at the IaaS service portal and APIs in each region.

For users to use services of each region including the user management function for local use, it is necessary to perform authentication with the user management function for local use and acquire tokens issued by this function.

For the determination of local services, use the list (URL) included in the catalog that is also returned at the time of authentication with the user management function for local use.

User management function for global use

The user management function for global use provides the authentication feature to use global services such as APIs for adding and updating groups to be global resources, and contract management.

For users to use global services, it is necessary to perform authentication with the user management function for global use and acquire tokens issued by this function.

For the determination of global services, use the list (URL) included in the catalog that is also returned at the time of authentication with the user management function for global use.

The following services are global services.
  • Global user management
  • Contract management
  • Global role management
  • Accounting management
  • Product management
  • Content delivery service
CAUTION:

The tokens authenticated with the user management function for global use are valid only for global services but cannot be used for local services.

By contrast, the tokens acquired with the user management function for local use are valid only for local services of the relevant region but cannot be used for global services and local services of other regions.

* As for client certificates, the function is not provided at the time when this document is released.