I agree deploy glance-registery should be protected environment, I think block glance-registery service via Firewall in gateway only can protected from internet attack, In internal network, I mean for theose insider, still have admin user also have non-admin user, if a malcious inside attacker which is a non-admin user(he has not admin priviledge), he can still cause DoS attack. BTW, because I see from above discussion, most foucs in admin user can attack, but for the vulnerability, non-admin insider user also can attack. On Fri, Mar 11, 2016 at 6:55 AM, Jeremy Stanley