Allow user and admin lock of an instance
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openstack-api-site |
Fix Released
|
Medium
|
Tom Fifield | ||
openstack-manuals |
Fix Released
|
Medium
|
Tom Fifield |
Bug Description
https:/
commit b5a01efd7a029fc
Author: Jason Dillaman <email address hidden>
Date: Fri Jul 19 16:04:34 2013 -0400
Allow user and admin lock of an instance
The existing instance lock capability is currently restricted
to being an admin-only action in the default policy. This
introduces additional functionality that allows the lock to be
used by users (to prevent accidental changes to an instance for
example), but also allows the lock to taken by an administrator
with appropriate privileges such that it overrides any lock held
by the user (for example to block actions on a rouge instance).
When unlocking an instance, an additional check is made to see if
the lock is held by user. If it isn't, an additional check is
made against the unlock_override policy.
Additionally added the current instance lock status to the
v3 extended status extension.
Blueprint mandatory-vm-lock
Flags: DocImpact
Change-Id: I5040276c2d9fd4
Changed in openstack-manuals: | |
milestone: | none → havana |
Changed in openstack-manuals: | |
status: | New → Confirmed |
importance: | Undecided → Medium |
policy.json examples need an update