diff options
author | ricolin <rico.lin@easystack.cn> | 2017-09-18 21:36:43 +0800 |
---|---|---|
committer | ricolin <rico.lin@easystack.cn> | 2017-12-01 01:34:55 +0800 |
commit | 46f0e16d11f5e0d008419e799e78bf72edec23c8 (patch) | |
tree | 2386a2378258c72b81fda537a855b862079cbe77 /etc | |
parent | 575a45b1c0debd1cdad186fa1675ac88f0f16541 (diff) | |
download | heat-46f0e16d11f5e0d008419e799e78bf72edec23c8.tar.gz |
[policy in code] part3 (resource types)
Allow use policy in code to resource type's rule.
Also add test for override the in-code resource type rule in json
file.
Partially-Implements: bp policy-in-code
Change-Id: Id6c21732e66de6c421427ded98de52f5da0a4db2
Diffstat (limited to 'etc')
-rw-r--r-- | etc/heat/policy.json | 18 |
1 files changed, 1 insertions, 17 deletions
diff --git a/etc/heat/policy.json b/etc/heat/policy.json index 3c85e1df2..9fbf21a80 100644 --- a/etc/heat/policy.json +++ b/etc/heat/policy.json @@ -47,21 +47,5 @@ "software_deployments:delete": "rule:deny_stack_user", "software_deployments:metadata": "", - "service:index": "rule:context_is_admin", - - "resource_types:OS::Nova::Flavor": "rule:project_admin", - "resource_types:OS::Cinder::EncryptedVolumeType": "rule:project_admin", - "resource_types:OS::Cinder::VolumeType": "rule:project_admin", - "resource_types:OS::Cinder::Quota": "rule:project_admin", - "resource_types:OS::Neutron::Quota": "rule:project_admin", - "resource_types:OS::Nova::Quota": "rule:project_admin", - "resource_types:OS::Manila::ShareType": "rule:project_admin", - "resource_types:OS::Neutron::ProviderNet": "rule:project_admin", - "resource_types:OS::Neutron::QoSPolicy": "rule:project_admin", - "resource_types:OS::Neutron::QoSBandwidthLimitRule": "rule:project_admin", - "resource_types:OS::Neutron::Segment": "rule:project_admin", - "resource_types:OS::Nova::HostAggregate": "rule:project_admin", - "resource_types:OS::Cinder::QoSSpecs": "rule:project_admin", - "resource_types:OS::Cinder::QoSAssociation": "rule:project_admin", - "resource_types:OS::Keystone::*": "rule:project_admin" + "service:index": "rule:context_is_admin" } |