Project hosts

Manage project host access and RAM

Delegate host access and understand shared-pool tiers, private-host RAM defaults, and per-project caps.

What host access controls

Host access controls who may place projects on a private dedicated host and who may administer that host. It is separate from project collaborators: a user can collaborate on a project without being able to create their own projects on the host, and a host user can place their own projects without being a collaborator on every existing project.

Roles

Use Access on the host drawer to add users or managers by account. Use Remove to revoke delegated access.

Public shared pool

Admins can put a host in the public shared pool by enabling the shared-pool policy and setting a tier. Any user with project-host tier greater than or equal to that value may place projects there without a delegated access row.

Use this for shared fleet capacity. Use delegated access for a private host that should only be usable by a known set of people.

Per-project RAM cap

The host Access tab includes Project resource policy, where an owner or manager can set an optional RAM cap for each project running on the host.

All projects share the host's physical RAM. Setting a per-project cap does not reserve that amount for every project. Plan for the number of projects that will run together, and leave headroom for the project host itself, filesystem cache, backups, and runtime services.

The cap covers memory used across the project's running processes, including notebook kernels, terminals, databases, and agents.

Agent notes

When answering access questions:

  1. Distinguish host access from project collaborators.
  2. Check whether the host is private, delegated, or public shared-pool.
  3. For "why can't I move/create here?", check delegated access, membership host tier, host status, placement availability, and region filters.
  4. For RAM questions, compare the per-project RAM cap with host RAM and the number of projects expected to run concurrently.
  5. Host access mutations require fresh auth and must route to the host-owning bay.