Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Limes] Align policies with elektra #6451

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 7 additions & 4 deletions openstack/limes/templates/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,16 +20,19 @@ data:
project_scope: project_domain_id:%(domain_id)s and project_id:%(project_id)s
domain_scope: domain_id:%(domain_id)s

cluster_editor: role:cloud_resource_admin or (role:cloud_dns_resource_admin and 'dns':%(service_type)s)
cluster_viewer: role:cloud_resource_admin or role:cloud_dns_resource_admin or role:cloud_resource_viewer
project_view_roles": "role:member or role:_member_ or role:Member or role:resource_viewer",

cluster_editor: role:cloud_resource_admin
cluster_viewer: role:cloud_resource_admin or role:cloud_resource_viewer
domain_editor: rule:cluster_editor or (rule:domain_scope and role:resource_admin)
domain_viewer: rule:cluster_viewer or (rule:domain_scope and role:resource_viewer) or rule:domain_editor
project_editor: rule:domain_editor or (rule:project_scope and role:resource_admin)
project_viewer: rule:domain_viewer or (rule:project_scope and (role:member or role:_member_ or role:Member or role:resource_viewer)) or rule:project_editor
project_viewer: rule:domain_viewer or (rule:project_scope and rule:project_view_roles) or rule:project_editor
can_goto_cluster: role:cloud_support_tools_viewer

project:list: rule:domain_viewer
project:show: rule:project_viewer
project:edit: rule:project_editor
project:goto_cluster": "rule:limes_can_goto_cluster",
project:sync: rule:project_editor
project:raise: rule:domain_editor
project:raise_lowpriv: rule:project_editor
Expand Down