Admin portion of the API requires RBAC

Bug #1266454 reported by Flavio Percoco
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
zaqar
Invalid
High
Unassigned

Bug Description

Enforce AuthZ for the admin portion of the API, meaning only users with some specific Keystone roles, as configured in marconi.conf, should be able to access the control plane.

Changed in marconi:
importance: Undecided → High
assignee: nobody → Flavio Percoco (flaper87)
milestone: none → icehouse-2
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to marconi (master)

Fix proposed to branch: master
Review: https://review.openstack.org/65072

Changed in marconi:
status: New → In Progress
Revision history for this message
Kurt Griffiths (kgriffs) wrote : Re: Health endpoint should be admin only

This fix will be made in conjuction with creating a new /ping endpoint in v1.1 of the api.

Kurt Griffiths (kgriffs)
no longer affects: marconi/icehouse
Changed in marconi:
milestone: icehouse-3 → none
Kurt Griffiths (kgriffs)
summary: - Health endpoint should be admin only
+ Admin portion of the API requires RBAC
Revision history for this message
Kurt Griffiths (kgriffs) wrote :

OK, so we need a way to enforce AuthZ for the admin portion of the API, meaning only users with some specific Keystone roles, as configured in marconi.conf, should be able to access the control plane.

Changed in marconi:
status: In Progress → Triaged
Kurt Griffiths (kgriffs)
description: updated
Revision history for this message
Flavio Percoco (flaper87) wrote :

I'm closing this bug in favor of the blueprint `marconi-rbac-support`. Please, refer to the blueprint for updates on this feature/bug.

no longer affects: marconi/juno
Changed in marconi:
milestone: juno-3 → none
assignee: Flavio Percoco (flaper87) → nobody
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.