Document rationale for protection testing in tempest

Bug #1926344 reported by Lance Bragstad
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tempest
Confirmed
Low
Unassigned

Bug Description

During the Xena PTG, we discussed the efforts to test secure RBAC in tempest [0].

We've always questioned if tempest is the right place for this sort of testing since it's configurable. At the same time, we've taken steps to remove the need for operators to re-invent the wheel for policy, and we're continuing to work towards that goal by adopting default roles and scope types from keystone.

It might be worthwhile to add a short section to the Tempest field guide that describes this level of testing and why it lives in tempest so that people aren't confused by it in the future.

[0] https://etherpad.opendev.org/p/policy-popup-xena-ptg

Revision history for this message
Martin Kopec (mkopec) wrote :

sounds reasonable

Changed in tempest:
importance: Undecided → Low
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.