Bug 1326392

Summary: [RFE] Implement Secure RBAC Project Scoped Personas within glance
Product: Red Hat OpenStack Reporter: Jaison Raju <jraju>
Component: openstack-glanceAssignee: Abhishek Kekane <akekane>
Status: CLOSED ERRATA QA Contact: msava
Severity: medium Docs Contact: Jenny-Anne Lynch <jelynch>
Priority: high    
Version: 7.0 (Kilo)CC: akekane, athomas, broose, cylopez, cyril, djuran, eglynn, gcharot, gfidente, igarciam, jelynch, jraju, jschluet, mariel, mburns, molasaga, morazi, msava, nkinder, nlevinki, nsatsia, pveiga, scohen, spower, srevivo, udesale, yrabl
Target Milestone: gaKeywords: FutureFeature, Triaged
Target Release: 17.1Flags: akekane: needinfo-
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openstack-glance-22.1.0-0.20210917121835.8499efd.el8ost Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-08-16 01:09:22 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1228474, 1801416, 2192190, 2192191, 2192193    
Bug Blocks: 1381612, 1936302    

Description Jaison Raju 2016-04-12 15:01:20 UTC
1. Proposed title of this feature request  
Need glance policy to be configured to include a read-only role .
  
3. What is the nature and description of the request?  
Customer has requirement of read-only admin role for all core services .

4. Why does the customer need this? (List the business requirements here)  
  A read-only admin user is necessary for customer environment .
  
Additional info:
The following bug is raised for keystone to add role .
This role can be configured in policy file .
Bug 1228474 - [RFE] Read only role for tenant access (edit) 
https://blueprints.launchpad.net/keystone/+spec/admin-readonly-role

Comment 3 Cyril Roelandt 2016-04-15 15:01:24 UTC
Hi,

I must say I agree with Jamie Lennox's comment on this other bug: https://bugzilla.redhat.com/show_bug.cgi?id=1228474 . Defining roles really seems to be up to the user, or to the installer. I don't think such a change would be welcome upstream, nor could we easily maintain it downstream. Maybe this should be re-targeted to the installer? What do you think?

Comment 9 Cyril Roelandt 2020-09-03 18:23:37 UTC
@rmascena This used to be a Glance bug, then it became a director bug, and you've just move it to Glance again. What has changed since we last discussed this bug?

Comment 15 Gregory Charot 2021-04-14 10:20:37 UTC
*** Bug 1901689 has been marked as a duplicate of this bug. ***

Comment 18 Abhishek Kekane 2021-06-30 14:02:09 UTC
NOTE:

We have completed implementation of project member and project reader role for all APIs except metadef in wallaby cycle.
Admin will continue to work as it is working earlier and will be modified once system scope is introduced.

Comment 23 Cyril Roelandt 2021-11-24 21:42:59 UTC
The Glance part of this feature can probably be tested already using the latest RPM.


@Lance: should we have a separate bug for the THT work?

Comment 36 Lukas Svaty 2023-06-16 08:13:29 UTC
Bulk moving target milestone to GA after the release of Beta on 14th June '23.

Comment 45 errata-xmlrpc 2023-08-16 01:09:22 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Release of components for Red Hat OpenStack Platform 17.1 (Wallaby)), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2023:4577

Comment 46 Red Hat Bugzilla 2023-12-15 04:25:02 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days