Comment 10 for bug 1010547

Revision history for this message
Brian Waldon (bcwaldon) wrote : Re: Admin rights escalate to other tenants (was: glance allows to delete arbitrary images)

I agree with Joe here, this is a future improvement, not a bug. However, we do need to be clear with that the implications of assigning a user an admin-like role entails.

As for future work, we need to separate service-level admin vs tenant-level admin. Right now, we create something that looks like a tenant-level admin, when it has the ability to act as if it were service-level.