security group

A security group acts as a virtual firewall for servers and other resources on a network. It is a container for security group rules which specify the network access rules.

Compute v2, Network v2

security group create

Create a new security group

openstack security group create
    [--description <description>]
    [--project <project> [--project-domain <project-domain>]]
    [--tag <tag> | --no-tag]
--description <description>

Security group description

--project <project>

Owner’s project (name or ID)

Network version 2 only

--project-domain <project-domain>

Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.

Network version 2 only

--tag <tag>

Tag to be added to the security group (repeat option to set multiple tags)

Network version 2 only


No tags associated with the security group

Network version 2 only


New security group name

security group delete

Delete security group(s)

openstack security group delete
    <group> [<group> ...]

Security group(s) to delete (name or ID)

security group list

List security groups

openstack security group list
    [--project <project> [--project-domain <project-domain>]]
    [--tags <tag>[,<tag>,...]] [--any-tags <tag>[,<tag>,...]]
    [--not-tags <tag>[,<tag>,...]] [--not-any-tags <tag>[,<tag>,...]]

Display information from all projects (admin only)

Network version 2 ignores this option and will always display information for all projects (admin only).

--project <project>

List security groups according to the project (name or ID)

Network version 2 only

--project-domain <project-domain>

Domain the project belongs to (name or ID). This can be used in case collisions between project names exist.

Network version 2 only

--tags <tag>[,<tag>,...]

List security groups which have all given tag(s)

Network version 2 only

--any-tags <tag>[,<tag>,...]

List security groups which have any given tag(s)

Network version 2 only

--not-tags <tag>[,<tag>,...]

Exclude security groups which have all given tag(s)

Network version 2 only

--not-any-tags <tag>[,<tag>,...]

Exclude security groups which have any given tag(s)

Network version 2 only

security group set

Set security group properties

openstack security group set
    [--name <new-name>]
    [--description <description>]
    [--tag <tag>] [--no-tag]
--name <new-name>

New security group name

--description <description>

New security group description

--tag <tag>

Tag to be added to the security group (repeat option to set multiple tags)


Clear tags associated with the security group. Specify both –tag and –no-tag to overwrite current tags


Security group to modify (name or ID)

security group show

Display security group details

openstack security group show

Security group to display (name or ID)

security group unset

Unset security group properties

openstack security group unset
    [--tag <tag> | --all-tag]
--tag <tag>

Tag to be removed from the security group (repeat option to remove multiple tags)


Clear all tags associated with the security group


Security group to modify (name or ID)