nova policy.json undocumented

Bug #922147 reported by Lorin Hochstein
30
This bug affects 5 people
Affects Status Importance Assigned to Milestone
OpenStack Compute (nova)
Invalid
Undecided
Unassigned
openstack-manuals
Fix Released
High
Lorin Hochstein

Bug Description

There seems to be a new access policy feature in nova that's controlled by etc/nova/policy.json that isn't currently documented.

Revision history for this message
Anne Gentle (annegentle) wrote :

Hi Lorin - Access to the api? Or is this the "short term AuthZ" from this blueprint http://wiki.openstack.org/ShortTermAuthZinNova? Would like your thoughts on it.

Changed in openstack-manuals:
status: New → Incomplete
Changed in nova:
status: New → Incomplete
Revision history for this message
Lorin Hochstein (lorinh) wrote :

I believe this is short term Authz. The initial commit message for this json file makes reference to this blueprint: https://blueprints.launchpad.net/nova/+spec/interim-nova-authz-service

commit ace0252d75fa169df3eb1c7171c122e8733649a7
Author: Brian Waldon <email address hidden>
Date: Fri Dec 30 13:11:56 2011 -0800

    Add policy checks to Compute.API

     * Second step of blueprint interim-nova-authz-service
     * Adds policy.json to define policy
     * Add nova.policy.wrap_enforce decorator
     * wrap majority of compute api functions with wrap_enforce

Revision history for this message
Anne Gentle (annegentle) wrote :

Brian, maybe you can comment further on what needs changed in the docs for people to be able to authorize.

Changed in nova:
status: Incomplete → Confirmed
Changed in openstack-manuals:
status: Incomplete → Confirmed
Anne Gentle (annegentle)
summary: - nova policy.json undocumented
+ nova policy.json undocumented, also affects quota documentation
summary: - nova policy.json undocumented, also affects quota documentation
+ nova policy.json undocumented
Tom Fifield (fifieldt)
Changed in openstack-manuals:
importance: Undecided → High
Revision history for this message
Lorin Hochstein (lorinh) wrote :

I'm on it...

Changed in openstack-manuals:
assignee: nobody → Lorin Hochstein (lorinh)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to openstack-manuals (master)

Fix proposed to branch: master
Review: https://review.openstack.org/7606

Changed in openstack-manuals:
status: Confirmed → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to openstack-manuals (master)

Reviewed: https://review.openstack.org/7606
Committed: http://github.com/openstack/openstack-manuals/commit/cf3c73f3caa95eeb83b5eb43de9e04585c6cecbb
Submitter: Jenkins
Branch: master

commit cf3c73f3caa95eeb83b5eb43de9e04585c6cecbb
Author: Lorin Hochstein <email address hidden>
Date: Thu May 17 11:42:39 2012 -0400

    Describe basic Keystone concepts

    Fixes bug 922147.

    Change-Id: I3f8a1456846fe4ae02e564ea228c9ebf0f7dc216

Changed in openstack-manuals:
status: In Progress → Fix Committed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to openstack-manuals (stable/essex)

Fix proposed to branch: stable/essex
Review: https://review.openstack.org/7650

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to openstack-manuals (stable/essex)

Reviewed: https://review.openstack.org/7650
Committed: http://github.com/openstack/openstack-manuals/commit/f316a7064c1216cee90f55320a92bed2d2071089
Submitter: Jenkins
Branch: stable/essex

commit f316a7064c1216cee90f55320a92bed2d2071089
Author: Lorin Hochstein <email address hidden>
Date: Thu May 17 11:42:39 2012 -0400

    Describe basic Keystone concepts

    Fixes bug 922147.

    Cherry picked from https://review.openstack.org/7606

    Change-Id: I3f8a1456846fe4ae02e564ea228c9ebf0f7dc216

tags: added: in-stable-essex
Tom Fifield (fifieldt)
Changed in nova:
status: Confirmed → Fix Released
Changed in openstack-manuals:
status: Fix Committed → Fix Released
Revision history for this message
Thierry Carrez (ttx) wrote :

Fix is not in nova

Changed in nova:
status: Fix Released → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.