Cannot reparent projects

Bug #1840090 reported by Adrian Turjak
14
This bug affects 3 people
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
New
Wishlist
Unassigned

Bug Description

For a variety of reasons Keystone needs the ability to 'safely' reparent a project (and children).

This should be able to be done via and API, and should be able to be done on an enabled project.

It should invalidate any tokens related to that project (and children) as well.

Revision history for this message
Adam Young (ayoung) wrote :

This is a non trivial request with severe security ramifications. Please expand on the rationale before continueing.

Changed in keystone:
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for OpenStack Identity (keystone) because there has been no activity for 60 days.]

Changed in keystone:
status: Incomplete → Expired
Revision history for this message
Colleen Murphy (krinkle) wrote :

This is still a valid request, we just need to discuss whether there is a way forward on it.

Changed in keystone:
importance: Undecided → Wishlist
status: Expired → New
Revision history for this message
Yang Youseok (ileixe) wrote :

Is there any progress on this issue? I found this from the past discussion (https://etherpad.openstack.org/p/PVG-Change-ownership-of-resources)

I think it's one of the most valuable (and missing) feature in openstack, and personally willing to take actions if there is some guidance.

Revision history for this message
Adrian Turjak (adriant-y) wrote :

ayoung proposed a spec for this which I rewrote:
https://review.opendev.org/#/c/618144/

^ that covers the implementation I was suggesting. I've sadly been out of the loop but if pinged on IRC or via email will respond and am happy to work on this feature or at the very least want to review/test it.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.