OpenStack Image Registry and Delivery Service (Glance)

Interim AuthZ service for Glance

Registered by Brian Waldon on 2012-01-17

Until Keystone is fully functional with AuthZ support, we may need some primitive authZ in Glance.

Description of the proposed implementation is here: http://etherpad.openstack.org/rbac-brain

This is similar to Nova's authz blueprint: https://blueprints.launchpad.net/nova/+spec/interim-nova-authz-service

Blueprint information

Status:
Complete
Approver:
Jay Pipes
Priority:
Medium
Drafter:
Brian Waldon
Direction:
Approved
Assignee:
Brian Waldon
Definition:
Approved
Series goal:
Accepted for essex
Implementation:
Implemented
Milestone target:
milestone icon 2012.1
Started by
Jay Pipes on 2012-01-17
Completed by
Thierry Carrez on 2012-01-25

Related branches

Sprints

Whiteboard

Gerrit topic: https://review.openstack.org/#q,topic:bp/interim-glance-authz-service,n,z

Addressed by: https://review.openstack.org/3130
    Add policy checking for basic image operations

NOTE(jrp): Documentation on how to write the policy file is still needed...

(?)

Work Items

This blueprint contains Public information 
Everyone can see this information.

Subscribers

No subscribers.