magnum/magnum/common/policies
ricolin 5971243169 Support enables rbac policies new defaults
The Magnum service allow enables policies (RBAC) new defaults and scope by
default. The Default value of config options ``[oslo_policy] enforce_scope``
and ``[oslo_policy] oslo_policy.enforce_new_defaults`` are both to
``False``, but will change to ``True`` in following cycles.

To enable them then modify the below config options value in
``magnum.conf`` file::

  [oslo_policy]
  enforce_new_defaults=True
  enforce_scope=True

reference tc goal for more detail:
https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html

Related blueprint secure-rbac

Change-Id: I249942a355577c4f1ef51b3988f0cc4979959d0b
2023-08-30 00:35:24 +08:00
..
__init__.py Drop bay and baymodel from magnum 2023-05-09 13:59:57 +00:00
base.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
certificate.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
cluster.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
cluster_template.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
federation.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
magnum_service.py Register default magnum service and stat policies in code 2017-10-23 02:57:29 +00:00
nodegroup.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
quota.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00
stats.py Support enables rbac policies new defaults 2023-08-30 00:35:24 +08:00