Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1304025 - [RFE] Permit modifying policy.json files for openstack services based on config needs
[RFE] Permit modifying policy.json files for openstack services based on conf...
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates (Show other bugs)
12.0 (Pike)
x86_64 Linux
medium Severity medium
: Upstream M1
: 12.0 (Pike)
Assigned To: Emilien Macchi
Gurenko Alex
: FutureFeature, Triaged
: 1304024 (view as bug list)
Depends On:
Blocks: 1442136 1469578
  Show dependency treegraph
 
Reported: 2016-02-02 12:12 EST by Freddy Wissing
Modified: 2018-03-16 19:07 EDT (History)
11 users (show)

See Also:
Fixed In Version: openstack-tripleo-heat-templates-7.0.0-0.20170419202046.el7ost
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-12-13 15:40:44 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
OpenStack gerrit 445700 None None None 2017-03-15 11:39 EDT
OpenStack gerrit 446039 None None None 2017-03-15 12:08 EDT
Red Hat Product Errata RHEA-2017:3462 normal SHIPPED_LIVE Red Hat OpenStack Platform 12.0 Enhancement Advisory 2018-02-15 20:43:25 EST

  None (edit)
Description Freddy Wissing 2016-02-02 12:12:56 EST
Customer use case is as a hosting provider requires control access and permission within the stack in a granular fashion.  The way that this is done (presently) is through the use of each component's policy.json file.  

The ability to automate this via puppet or heat template at time of deploy would be a nice feature to have as it would assist in consolidating the post deployment actions that are being done and allow for a structured approach in crafting specialized permissions.

====

Additional info

Due to the nature of hosting, this customer would like to have the ability to dictate during the initial data dump into director to add the configuration changes to each components policy.json file.  This would allow for the services to be hardened at the time of deployment rather than either being scripted out later or a manual process post deploy.
Comment 2 Mike Burns 2016-02-03 11:43:20 EST
*** Bug 1304024 has been marked as a duplicate of this bug. ***
Comment 3 Mike Burns 2016-04-07 17:07:13 EDT
This bug did not make the OSP 8.0 release.  It is being deferred to OSP 10.
Comment 5 Emilien Macchi 2017-02-01 17:19:16 EST
The blueprint has been created upstream:https://blueprints.launchpad.net/tripleo/+spec/modify-policy-json

Target is pike-1 milestone for now.
Comment 6 Red Hat Bugzilla Rules Engine 2017-02-01 17:19:23 EST
This bugzilla has been removed from the release and needs to be reviewed and Triaged for another Target Release.
Comment 7 Red Hat Bugzilla Rules Engine 2017-03-13 00:45:40 EDT
This bugzilla has been removed from the release and needs to be reviewed and Triaged for another Target Release.
Comment 15 Gurenko Alex 2017-11-23 06:38:50 EST
Verified on build 2017-11-20.1. Update scenario verified on 2017-11-20.1 -> 2017-11.22.7
Comment 18 errata-xmlrpc 2017-12-13 15:40:44 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:3462

Note You need to log in before you can comment on or make changes to this bug.