Bug 1401393

Summary: [RFE] Security groups managed by admin should get applied by default to all instances.
Product: Red Hat OpenStack Reporter: Pratik Pravin Bandarkar <pbandark>
Component: openstack-neutronAssignee: Assaf Muller <amuller>
Status: CLOSED WONTFIX QA Contact: Toni Freger <tfreger>
Severity: medium Docs Contact:
Priority: medium    
Version: 10.0 (Newton)CC: amuller, chrisw, cshastri, ealcaniz, jraju, markmc, mburns, mnadeem, molasaga, nyechiel, pmorey, srevivo
Target Milestone: ---Keywords: FutureFeature, RFE
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-02-14 15:00:16 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 1381612    

Description Pratik Pravin Bandarkar 2016-12-05 06:42:00 UTC
1. Proposed title of this feature request  
[RFE] Security groups managed by admin should get applied by default to all instances. 
     

3. What is the nature and description of the request?  
- The security group created by admin, should not be manipulated by any other user.
- If any user spawn instance in the tenant, then some security group created by admin should get applied to the instance. There should not be any option for user to bypass the security group created by admin.

Comment 5 Assaf Muller 2017-09-27 19:37:07 UTC
*** Bug 1496254 has been marked as a duplicate of this bug. ***

Comment 7 Assaf Muller 2018-02-14 15:00:16 UTC
I'm going ahead and close this RFE. It's been around for years, and every so often we discuss it upstream and it ends up being rejected. The main claim against the validity of this RFE is that it'll cause divergence between different OpenStack clouds / go against interoperability. I think it's more truthful to close this RFE than let is sit here for years with no response. It's become clear over time that this RFE will not be implemented in Neutron's security groups API.