patrole/releasenotes/notes/volume-type-encryption-poli...

20 lines
795 B
YAML

---
features:
- |
Added new Cinder feature flag (``CONF.policy_feature_enabled.added_cinder_policies_stein``)
for the following newly introduced granular Cinder policies:
- ``volume_extension:volume_type_encryption:create``
- ``volume_extension:volume_type_encryption:get``
- ``volume_extension:volume_type_encryption:update``
- ``volume_extension:volume_type_encryption:delete``
The corresponding Patrole test cases are modified to support
the granularity. The test cases also support backward
compatibility with the old single rule:
``volume_extension:volume_type_encryption``
The ``rules`` parameter in ``rbac_rule_validation.action``
decorator now also accepts a list of callables; each callable
should return a policy action (str).