Images belongs to "projects" within OpenStack, and they can be shared with other projects if the same image is needed in multiple projects. The sharing-process is a two-step approach:

  1. The project owning the image need to share it with the other project
  2. The receiving project need to accept the image to be able to use it.

The motivation behind this two-step approach is to ensure that a malicious actor is unable to pollute a projects image-list with malicious images.

Share an image with another project

To be able to share an image with a project you would need the other projects "ID". You can determine the ID of projects you have access to using the CLI:

$ openstack project list
+----------------------------------+-----------------+
| ID                               | Name            |
+----------------------------------+-----------------+
| 64e7161e9e8946ecbc51a24c0f0b2619 | MISC            |
| e305b450c48e455b962ef1513d7f0e3f | PRIV_eigilo     |
+----------------------------------+-----------------+

When you know the ID of a project you want to share the image with you can share it like so:

$ openstack image list --shared 
+--------------------------------------+--------------+--------+
| ID                                   | Name         | Status |
+--------------------------------------+--------------+--------+
| e584789b-9483-4503-ba89-146a62f68ea1 | Eigils Jammy | active |
+--------------------------------------+--------------+--------+
$ openstack image add project "Eigils Jammy" 64e7161e9e8946ecbc51a24c0f0b2619
+------------+--------------------------------------+
| Field      | Value                                |
+------------+--------------------------------------+
| created_at | 2025-10-13T12:03:05Z                 |
| image_id   | e584789b-9483-4503-ba89-146a62f68ea1 |
| member_id  | 68036508be864a038744f3a0a9c9cfc1     |
| schema     | /v2/schemas/member                   |
| status     | pending                              |
| updated_at | 2025-10-13T12:03:05Z                 |
+------------+--------------------------------------+

You can display what projects your image is shared with:

$ openstack image member list e584789b-9483-4503-ba89-146a62f68ea1
+--------------------------------------+----------------------------------+----------+
| Image ID                             | Member ID                        | Status   |
+--------------------------------------+----------------------------------+----------+
| e584789b-9483-4503-ba89-146a62f68ea1 | 68036508be864a038744f3a0a9c9cfc1 | accepted |
| e584789b-9483-4503-ba89-146a62f68ea1 | 64e7161e9e8946ecbc51a24c0f0b2619 | pending  |
+--------------------------------------+----------------------------------+----------+


Accept a shared image

Before a shared image can be used it has to be accepted. You can see images shared with your project like so:

$ openstack image list --member-status pending  --shared 
+--------------------------------------+--------------+--------+
| ID                                   | Name         | Status |
+--------------------------------------+--------------+--------+
| e584789b-9483-4503-ba89-146a62f68ea1 | Eigils Jammy | active |
+--------------------------------------+--------------+--------+

The image can be accepted with the following command:

$ openstack image set --accept e584789b-9483-4503-ba89-146a62f68ea1


  • No labels