Bug 1465569
Summary: | [RFE] Provide a global ‘lock down your overcloud’ feature/setting | ||
---|---|---|---|
Product: | Red Hat OpenStack | Reporter: | Jon Thomas <jthomas> |
Component: | rhosp-director | Assignee: | RHOS Maint <rhos-maint> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | 11.0 (Ocata) | CC: | aschultz, bnemec, dbecker, dcaspin, jslagle, kecarter, mburns, morazi |
Target Milestone: | --- | Keywords: | FutureFeature, Triaged |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-04-30 20:11:00 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jon Thomas
2017-06-27 16:17:58 UTC
Note that we already document a method to prevent deletion of the overcloud: https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/11/html/director_installation_and_usage/chap-performing_tasks_after_overcloud_creation#sect-Protecting_the_Overcloud_from_Removal This wouldn't stop an admin from deleting a nova instance or a neutron port, although a similar technique could probably be used for those services' policy.json. Pushing out of OSP13, the locks will need to be revisited in other services. This bug can serve as tracker for future work. After review between PM and engineering we have decided to close this RFE due to a lack of capacity. Please reopen this issue if you feel it still needs to be addressed and request re evaluation. |