One idea is to make the policies used by is_cloud_admin() and is_domain_admin() configurable. We can use 'admin_required' as a default value. It behaves in a backward-compatible way.
I am not sure this is the right direction or not. If we need to do more than the above idea, folks familiar with keystone needs to be involved.
One idea is to make the policies used by is_cloud_admin() and is_domain_admin() configurable. We can use 'admin_required' as a default value. It behaves in a backward-compatible way.
I am not sure this is the right direction or not. If we need to do more than the above idea, folks familiar with keystone needs to be involved.