filesystem.acltemplate.create¶
Create a new filesystem ACL template.
No Additional Items
Tuple Validation
Parameter 1: acltemplate_create
acltemplate_create
Type: objectACL template configuration data for the new template.
No Additional PropertiesName
Type: stringHuman-readable name for the ACL template.
Acltype
Type: enum (of string)ACL type this template provides.
Must be one of:
- "NFS4"
- "POSIX1E"
Acl
Array of Access Control Entries defined by this template.
No Additional Items
Each item of this array must be:
NFS4ACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Subject type for this ACE.
owner@
: File/directory ownergroup@
: File/directory primary groupeveryone@
: All usersUSER
: Specific user accountGROUP
: Specific group
Must be one of:
- "owner@"
- "group@"
- "everyone@"
- "USER"
- "GROUP"
Type
Type: enum (of string)Access control type.
ALLOW
: Grant the specified permissionsDENY
: Explicitly deny the specified permissions
Must be one of:
- "ALLOW"
- "DENY"
Perms
Permissions granted or denied by this ACE.
NFS4ACE_AdvancedPerms
Type: objectNo Additional Properties
Read Data
Type: boolean Default: falsePermission to read file data or list directory contents.
Write Data
Type: boolean Default: falsePermission to write file data or create files in directory.
Append Data
Type: boolean Default: falsePermission to append data to files or create subdirectories.
Read Named Attrs
Type: boolean Default: falsePermission to read named attributes (extended attributes).
Write Named Attrs
Type: boolean Default: falsePermission to write named attributes (extended attributes).
Execute
Type: boolean Default: falsePermission to execute files or traverse directories.
Delete
Type: boolean Default: falsePermission to delete the file or directory.
Delete Child
Type: boolean Default: falsePermission to delete child files within a directory.
Read Attributes
Type: boolean Default: falsePermission to read basic file attributes (size, timestamps, etc.).
Write Attributes
Type: boolean Default: falsePermission to write basic file attributes.
Read Acl
Type: boolean Default: falsePermission to read the Access Control List.
Write Acl
Type: boolean Default: falsePermission to modify the Access Control List.
Write Owner
Type: boolean Default: falsePermission to change the file owner.
Synchronize
Type: boolean Default: falsePermission to use the file/directory as a synchronization primitive.
NFS4ACE_BasicPerms
Type: objectNo Additional Properties
Basic
Type: enum (of string)Basic permission level for NFS4 ACE.
FULL_CONTROL
: Full read, write, execute, and administrative permissionsMODIFY
: Read, write, and execute permissionsREAD
: Read-only permissionsTRAVERSE
: Execute/traverse permissions only
Must be one of:
- "FULL_CONTROL"
- "MODIFY"
- "READ"
- "TRAVERSE"
Flags
Inheritance and other behavioral flags for this ACE.
NFS4ACE_AdvancedFlags
Type: objectNo Additional Properties
File Inherit
Type: boolean Default: falseApply this ACE to files within directories.
Directory Inherit
Type: boolean Default: falseApply this ACE to subdirectories within directories.
No Propagate Inherit
Type: boolean Default: falseDo not propagate inheritance beyond immediate children.
Inherit Only
Type: boolean Default: falseThis ACE only affects inheritance, not the object itself.
Inherited
Type: boolean Default: falseThis ACE was inherited from a parent directory.
NFS4ACE_BasicFlags
Type: objectNo Additional Properties
Basic
Type: enum (of string)Basic inheritance behavior for NFS4 ACE.
INHERIT
: Apply to child files and directoriesNOINHERIT
: Do not apply to child objects
Must be one of:
- "INHERIT"
- "NOINHERIT"
Id
Default: nullUID or GID when tag
is "USER" or "GROUP". null
for special entries.
Value must be greater or equal to -1
and lesser or equal to 2147483647
Who
Default: nullUsername or group name when tag
is "USER" or "GROUP". null
for special entries.
Must be at least 1
characters long
No Additional Items
Each item of this array must be:
POSIXACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Subject type for this POSIX ACE.
USER_OBJ
: File/directory ownerGROUP_OBJ
: File/directory primary groupOTHER
: All other usersMASK
: Maximum permissions for named users and groupsUSER
: Specific user accountGROUP
: Specific group
Must be one of:
- "USER_OBJ"
- "GROUP_OBJ"
- "OTHER"
- "MASK"
- "USER"
- "GROUP"
POSIXACE_Perms
Type: objectRead, write, and execute permissions for this ACE.
No Additional PropertiesRead
Type: booleanPermission to read file contents or list directory contents.
Write
Type: booleanPermission to write file contents or create/delete files in directory.
Execute
Type: booleanPermission to execute files or traverse directories.
Default
Type: booleanWhether this is a default ACE that applies to newly created child objects.
Id
Default: nullNumeric user or group ID when tag is USER
or GROUP
. null
for object entries.
Value must be greater or equal to -1
and lesser or equal to 2147483647
Who
Default: nullUsername or group name when tag is USER
or GROUP
. null
for object entries.
Must be at least 1
characters long
Comment
Type: string Default: ""Optional descriptive comment about the template's purpose.
AclTemplateEntry
Type: objectThe created ACL template configuration.
No Additional PropertiesId
Type: integerUnique identifier for the ACL template.
Builtin
Type: booleanWhether this is a built-in system template or user-created.
Name
Type: stringHuman-readable name for the ACL template.
Acltype
Type: enum (of string)ACL type this template provides.
Must be one of:
- "NFS4"
- "POSIX1E"
Acl
Array of Access Control Entries defined by this template.
No Additional Items
Each item of this array must be:
NFS4ACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Subject type for this ACE.
owner@
: File/directory ownergroup@
: File/directory primary groupeveryone@
: All usersUSER
: Specific user accountGROUP
: Specific group
Must be one of:
- "owner@"
- "group@"
- "everyone@"
- "USER"
- "GROUP"
Type
Type: enum (of string)Access control type.
ALLOW
: Grant the specified permissionsDENY
: Explicitly deny the specified permissions
Must be one of:
- "ALLOW"
- "DENY"
Perms
Permissions granted or denied by this ACE.
NFS4ACE_AdvancedPerms
Type: objectNo Additional Properties
Read Data
Type: boolean Default: falsePermission to read file data or list directory contents.
Write Data
Type: boolean Default: falsePermission to write file data or create files in directory.
Append Data
Type: boolean Default: falsePermission to append data to files or create subdirectories.
Read Named Attrs
Type: boolean Default: falsePermission to read named attributes (extended attributes).
Write Named Attrs
Type: boolean Default: falsePermission to write named attributes (extended attributes).
Execute
Type: boolean Default: falsePermission to execute files or traverse directories.
Delete
Type: boolean Default: falsePermission to delete the file or directory.
Delete Child
Type: boolean Default: falsePermission to delete child files within a directory.
Read Attributes
Type: boolean Default: falsePermission to read basic file attributes (size, timestamps, etc.).
Write Attributes
Type: boolean Default: falsePermission to write basic file attributes.
Read Acl
Type: boolean Default: falsePermission to read the Access Control List.
Write Acl
Type: boolean Default: falsePermission to modify the Access Control List.
Write Owner
Type: boolean Default: falsePermission to change the file owner.
Synchronize
Type: boolean Default: falsePermission to use the file/directory as a synchronization primitive.
NFS4ACE_BasicPerms
Type: objectNo Additional Properties
Basic
Type: enum (of string)Basic permission level for NFS4 ACE.
FULL_CONTROL
: Full read, write, execute, and administrative permissionsMODIFY
: Read, write, and execute permissionsREAD
: Read-only permissionsTRAVERSE
: Execute/traverse permissions only
Must be one of:
- "FULL_CONTROL"
- "MODIFY"
- "READ"
- "TRAVERSE"
Flags
Inheritance and other behavioral flags for this ACE.
NFS4ACE_AdvancedFlags
Type: objectNo Additional Properties
File Inherit
Type: boolean Default: falseApply this ACE to files within directories.
Directory Inherit
Type: boolean Default: falseApply this ACE to subdirectories within directories.
No Propagate Inherit
Type: boolean Default: falseDo not propagate inheritance beyond immediate children.
Inherit Only
Type: boolean Default: falseThis ACE only affects inheritance, not the object itself.
Inherited
Type: boolean Default: falseThis ACE was inherited from a parent directory.
NFS4ACE_BasicFlags
Type: objectNo Additional Properties
Basic
Type: enum (of string)Basic inheritance behavior for NFS4 ACE.
INHERIT
: Apply to child files and directoriesNOINHERIT
: Do not apply to child objects
Must be one of:
- "INHERIT"
- "NOINHERIT"
Id
Default: nullUID or GID when tag
is "USER" or "GROUP". null
for special entries.
Value must be greater or equal to -1
and lesser or equal to 2147483647
Who
Default: nullUsername or group name when tag
is "USER" or "GROUP". null
for special entries.
Must be at least 1
characters long
No Additional Items
Each item of this array must be:
POSIXACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Subject type for this POSIX ACE.
USER_OBJ
: File/directory ownerGROUP_OBJ
: File/directory primary groupOTHER
: All other usersMASK
: Maximum permissions for named users and groupsUSER
: Specific user accountGROUP
: Specific group
Must be one of:
- "USER_OBJ"
- "GROUP_OBJ"
- "OTHER"
- "MASK"
- "USER"
- "GROUP"
POSIXACE_Perms
Type: objectRead, write, and execute permissions for this ACE.
No Additional PropertiesRead
Type: booleanPermission to read file contents or list directory contents.
Write
Type: booleanPermission to write file contents or create/delete files in directory.
Execute
Type: booleanPermission to execute files or traverse directories.
Default
Type: booleanWhether this is a default ACE that applies to newly created child objects.
Id
Default: nullNumeric user or group ID when tag is USER
or GROUP
. null
for object entries.
Value must be greater or equal to -1
and lesser or equal to 2147483647
Who
Default: nullUsername or group name when tag is USER
or GROUP
. null
for object entries.
Must be at least 1
characters long
Comment
Type: string Default: ""Optional descriptive comment about the template's purpose.
Required roles: FILESYSTEM_ATTRS_WRITE