5971243169
The Magnum service allow enables policies (RBAC) new defaults and scope by default. The Default value of config options ``[oslo_policy] enforce_scope`` and ``[oslo_policy] oslo_policy.enforce_new_defaults`` are both to ``False``, but will change to ``True`` in following cycles. To enable them then modify the below config options value in ``magnum.conf`` file:: [oslo_policy] enforce_new_defaults=True enforce_scope=True reference tc goal for more detail: https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html Related blueprint secure-rbac Change-Id: I249942a355577c4f1ef51b3988f0cc4979959d0b
24 lines
708 B
Plaintext
24 lines
708 B
Plaintext
# Devstack settings
|
|
|
|
## Modify to your environment
|
|
# FLOATING_RANGE=192.168.1.224/27
|
|
# PUBLIC_NETWORK_GATEWAY=192.168.1.225
|
|
# PUBLIC_INTERFACE=em1
|
|
# FIXED_RANGE=10.0.0.0/24
|
|
## Log all output to files
|
|
# LOGFILE=$HOME/devstack.log
|
|
## Neutron settings
|
|
# Q_USE_SECGROUP=True
|
|
# ENABLE_TENANT_VLANS=True
|
|
# TENANT_VLAN_RANGE=
|
|
# PHYSICAL_NETWORK=public
|
|
# OVS_PHYSICAL_BRIDGE=br-ex
|
|
|
|
# This option controls whether or not to enforce scope when evaluating policies. Learn more:
|
|
# https://docs.openstack.org/oslo.policy/latest/configuration/index.html#oslo_policy.enforce_scope
|
|
MAGNUM_ENFORCE_SCOPE=$(trueorfalse False MAGNUM_ENFORCE_SCOPE)
|
|
|
|
# Enable Magnum services
|
|
enable_service magnum-api
|
|
enable_service magnum-cond
|