Comment 4 for bug 1517702

Revision history for this message
Haim Daniel (hdaniel) wrote :

Several thoughts here:

1. The described flow here is 'cutting the branch you are grew and sat on'. IMO it actually makes sense to forbid the default rule removal.

2.I think that in order to share the network, a user is not supposed to update the existing 'self shared' rbac rule. If he wishes to share the network, he simply would create an additional policy rule for that. (Or remove if the opposite behavior is needed).

3. A neater way to bugfix that, might be a default 'self sharing' rule creation upon the network rule creation (if not --shared flag is used)