Projects and Quotas
A project tag records which body of regulated work a virtual machine and its drives belong to. A quota is the share of CPU, memory, and storage your team has been allocated, which every running machine draws against. The tag is about classification; the quota is about capacity.
Why a project tag is a classification, not a label
The tag is applied when drives are mounted at boot. That is why changing the project of a running VM has no effect until the machine is restarted, even though the configuration shows the new tag immediately. tiCrypt is enforcing that a machine's regulatory classification is fixed for the life of a session, so a live machine cannot be reclassified out from under the data already open on it.
Classification is what makes the audit trail meaningful. An access record is only useful if it says what kind of data was accessed. Tagging machines and drives with projects is what lets an auditor answer "who touched material under this contract" rather than merely "who started a VM".
Forcing or removing a tag is a declassification action. It requires project-management permission and is recorded, because it changes the compliance status of everything on the machine.
Quota is charged for running instances only. A stopped configuration consumes no CPU or memory, only the storage of its drives. Keeping several configurations for different purposes is free; running them all at once is not.
Before you begin
- You are a member of the project you intend to apply, and are active in it.
- Declassifying requires permission to manage the project in question.
- The VM is powered off if you need the change to take effect immediately.
Set a Project in a Virtual Machine
- Go to the Virtual Machines icon in the top left taskbar.
- Click the VMs section on the top left panel.
- In the left panel, click the Open Full Menu button by the virtual machine to set a project for.
- Select Set Project.
- In the pop-up, select a project to tag the virtual machine.
- Click Classify.
Forcefully Set a Project in a Virtual Machine
- Go to the Virtual Machines icon in the top left taskbar.
- Click the VMs section on the top left panel.
- In the left panel, click the Open Full Menu button by the virtual machine to set a project for.
- Select Set Project.
- In the pop-up, select any project to tag the virtual machine.
- Click Force change with admin privilege.
Forcefully tagging a virtual machine with a project is only available to users with admin or super-admin roles in the system.
Changing a project tag on a running VM does not take effect until the VM is restarted, even if the VM configuration reflects the updated project tag.
Manage Projects from a Virtual Machine
- Go to the Virtual Machines icon in the top left taskbar.
- Click the VMs section on the top left panel.
- In the left panel, click the project tag on the virtual machine to manage.
- In the new window, click Open Overlay in the top right corner.
- In the pop-up, manage the Members, Member Certifications, Subprojects and Security Requirements of the project in the virtual machine.
Remove a Project from a Virtual Machine
- Go to the Virtual Machines icon in the top left taskbar.
- Click the VMs section on the top left panel.
- In the left panel, click the Open Full Menu button by the virtual machine to remove a project from.
- Select Set Project.
- In the pop-up, select No project (unlocked) to remove the project tag from the VM.
- Click Declassify.
If you are a super-admin and do not belong to the project, you can use the Force change with admin privilege option to forcibly remove a project tag.
View Live Quota Consumption of a Virtual Machine
- Go to the Virtual Machines icon in the top left taskbar.
- Click the VMs section on the top left panel.
- In the left panel, click the virtual machine to view the live quota consumption.
- Click the VM Settings and Details option in the center right.
- In the new window, view the following.
- CPU : Central Processing Unit of the VM.
- MEM : Memory used by the VM.
- IN : Amount of kilobytes received.
- OUT : Amount of kilobytes sent.
- DRIVE : Home drive usage.
- WARNING : Drive warnings and errors.
Edit Quota Consumption in a Virtual Machine
VM quotas are determined by the team's allocation. If you need more resources, ask your admin to adjust the team quota.
To edit the drive capacity of a virtual machine, create a new drive or a new virtual machine.
Repair an Unattached Drive in a Virtual Machine
- Go to the Virtual Machines icon in the top left taskbar.
- Click the VMs section on the top left panel.
- In the left panel, click the virtual machine with the drive to repair.
- Click the VM Settings and Details option in the bottom center.
- In the new window, under drive warnings, click the Repair button next to the drive warning.
If a drive is not working properly, consult your admin for guidance.