RDO tickets are now tracked in Jira https://issues.redhat.com/projects/RDO/issues/
Bug 965549 - heat RDO packages omit default policy.json
Summary: heat RDO packages omit default policy.json
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: RDO
Classification: Community
Component: openstack-heat
Version: unspecified
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: ---
Assignee: RHOS Maint
QA Contact: Amit Ugol
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-05-21 10:57 UTC by Steven Hardy
Modified: 2014-06-05 09:47 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2013-05-29 17:08:42 UTC
Embargoed:


Attachments (Terms of Use)

Description Steven Hardy 2013-05-21 10:57:30 UTC
Description of problem:
The heat packages in RDO don't include the /etc/heat/policy.json file, which results in a potentially less secure installation because access to the APIs is not restricted for the in-instance users

Version-Release number of selected component (if applicable):
openstack-heat-2013.1-1.3.fc19.src.rpm

How reproducible:
Always

Steps to Reproduce:
1. Install heat from RDO repos
2. Note that /etc/heat/policy.json is missing
3. See warning in API logs:
WARNING heat.common.policy [-] Unable to find policy file

Actual results:


Expected results:


Additional info:

Comment 1 Jeff Peeler 2013-05-29 17:08:42 UTC
This has been fixed in RDO, specifically in openstack-heat-common.


Note You need to log in before you can comment on or make changes to this bug.