diff --git a/etc/neutron/policy.d/neutron-fwaas.json b/etc/neutron/policy.d/neutron-fwaas.json index eb71e2568..2e6e05b7d 100644 --- a/etc/neutron/policy.d/neutron-fwaas.json +++ b/etc/neutron/policy.d/neutron-fwaas.json @@ -3,11 +3,6 @@ "shared_firewall_policies": "field:firewall_policies:shared=True", "shared_firewall_rules": "field:firewall_rules:shared=True", - "public_firewall_groups": "field:firewall_groups:public=True", - "public_firewall_policies": "field:firewall_policies:public=True", - "public_firewall_rules": "field:firewall_rules:public=True", - - "create_firewall": "", "update_firewall": "rule:admin_or_owner", "delete_firewall": "rule:admin_or_owner", @@ -18,16 +13,19 @@ "get_firewall": "rule:admin_or_owner or rule:shared_firewalls", + "shared_firewall_groups": "field:firewall_groups:shared=True", + "shared_firewall_policies": "field:firewall_policies:shared=True", + "shared_firewall_rules": "field:firewall_rules:shared=True", "create_firewall_group": "", "update_firewall_group": "rule:admin_or_owner", "delete_firewall_group": "rule:admin_or_owner", - "create_firewall_group:public": "rule:admin_only", - "update_firewall_group:public": "rule:admin_only", - "delete_firewall_group:public": "rule:admin_only", + "create_firewall_group:shared": "rule:admin_only", + "update_firewall_group:shared": "rule:admin_only", + "delete_firewall_group:shared": "rule:admin_only", - "get_firewall_group": "rule:admin_or_owner or rule:public_firewall_groups", + "get_firewall_group": "rule:admin_or_owner or rule:shared_firewall_groups", "create_firewall_policy": "", @@ -38,12 +36,7 @@ "update_firewall_policy:shared": "rule:admin_only", "delete_firewall_policy:shared": "rule:admin_only", - "create_firewall_policy:public": "rule:admin_only", - "update_firewall_policy:public": "rule:admin_only", - "delete_firewall_policy:public": "rule:admin_only", - - "get_firewall_policy": "rule:admin_or_owner or rule:shared_firewall_policies or rule:public_firewall_policies", - + "get_firewall_policy": "rule:admin_or_owner or rule:shared_firewall_policies", "create_firewall_rule": "", "update_firewall_rule": "rule:admin_or_owner", @@ -53,9 +46,5 @@ "update_firewall_rule:shared": "rule:admin_only", "delete_firewall_rule:shared": "rule:admin_only", - "create_firewall_rule:public": "rule:admin_only", - "update_firewall_rule:public": "rule:admin_only", - "delete_firewall_rule:public": "rule:admin_only", - - "get_firewall_rule": "rule:admin_or_owner or rule:shared_firewall_rules or rule:public_firewall_rules" + "get_firewall_rule": "rule:admin_or_owner or rule:shared_firewall_rules" }