*** mhen_ is now known as mhen | 01:34 | |
slaweq | hi keystone team | 06:11 |
---|---|---|
slaweq | I'm looking to start implementation of the MANAGER role in the Neutron's policies | 06:11 |
slaweq | and I wanted to ask if there is any documentation about this role somewhere? I only found patch https://review.opendev.org/c/openstack/keystone/+/822601 which adds this role during bootstrap process | 06:12 |
slaweq | I would for example know if MANAGER role somehow inherits privileges from e.g. MEMBER role? So if there was something like ADMIN <- MEMBER <- READER if now there is something like ADMIN <- MANAGER <- MEMBER <- READER ? | 06:13 |
gtema | Slaweq, afaik your perception of roles inheritance is right | 06:18 |
gtema | The only known documentation for me is srbac TC doc | 06:19 |
gtema | https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html that one | 06:20 |
gtema | From the doc: | 06:21 |
gtema | The project-manager needs to be added in the role implication so that the admin role implies manager, the manager role implies member, the member role implies reader. This needs the modification in the already merged keystone specification. | 06:21 |
slaweq | gtema (Artem Goncharov): thx, that one I know already :) | 06:27 |
slaweq | I was hoping that there is something more in keystone maybe | 06:27 |
gtema | I haven't seen anything | 06:27 |
slaweq | thx | 06:28 |
slaweq | that one will need to be enough then :) | 06:29 |
gtema | Lol | 06:29 |
opendevreview | Artem Goncharov proposed openstack/keystone master: Add JsonSchema to `credentials` https://review.opendev.org/c/openstack/keystone/+/923324 | 07:01 |
opendevreview | Artem Goncharov proposed openstack/keystone master: Add JsonSchema to `credentials` https://review.opendev.org/c/openstack/keystone/+/923324 | 07:02 |
frickler | d34dh0r53: looks like you missed https://review.opendev.org/c/openstack/releases/+/923114 which is due today, please have a look when you're back | 12:23 |
gtema | frickler - July 4th - he is off today | 12:24 |
frickler | yes, I saw that, hence the "when back" ;) | 12:24 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!