Bug 1465569 - [RFE] Provide a global ‘lock down your overcloud’ feature/setting
Summary: [RFE] Provide a global ‘lock down your overcloud’ feature/setting
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: rhosp-director
Version: 11.0 (Ocata)
Hardware: Unspecified
OS: Unspecified
low
medium
Target Milestone: ---
: ---
Assignee: RHOS Maint
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-06-27 16:17 UTC by Jon Thomas
Modified: 2022-10-03 14:26 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-04-30 20:11:00 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker OSP-243 0 None None None 2022-10-03 14:26:02 UTC

Description Jon Thomas 2017-06-27 16:17:58 UTC
Split out from https://bugzilla.redhat.com/show_bug.cgi?id=1396227

Provide a global ‘lock down your overcloud’ feature/setting

As an integrated feature or as a externally documented procedure, provide a way to prohib major overcloud changes. Externally documented methods could do something with IPMI passwords or PXE network traffic to prevent redeployments.

Comment 4 Ben Nemec 2017-08-09 15:35:04 UTC
Note that we already document a method to prevent deletion of the overcloud: https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/11/html/director_installation_and_usage/chap-performing_tasks_after_overcloud_creation#sect-Protecting_the_Overcloud_from_Removal

This wouldn't stop an admin from deleting a nova instance or a neutron port, although a similar technique could probably be used for those services' policy.json.

Comment 5 Jaromir Coufal 2017-08-10 20:07:19 UTC
Pushing out of OSP13, the locks will need to be revisited in other services. This bug can serve as tracker for future work.

Comment 6 Doron Caspin 2021-04-30 20:11:00 UTC
After review between PM and engineering we have decided to close this RFE due to a lack of capacity. Please reopen this issue if you feel it still needs to be addressed and request re evaluation.


Note You need to log in before you can comment on or make changes to this bug.