f9d2d574b5
The project is moving to support kilo in master. This requires that the cinder galaxy role be updated to support installing the kilo release of cinder. This commit makes changes not added by the minimum viable kilo install patch - https://review.openstack.org/#/c/166986/ Changes: cinder.conf - [DEFAULT] backup_metadata_version is now configurable because the version has changed. The default is 2, in juno it was 1. - [DEFAULT] client_socket_timeout is now configurable because the value has changed. The default is 900, in juno it was 0. - [profiler] profiler_enabled is now configurable but disabled by default. Although this feature is part of juno the api-paste.ini file was not updated in os-a-d juno to make use of it. - [profiler] trace_sqlalchemy is now configurable but disabled by default. - [DEFAULT] rabbit_port -> [oslo_messaging_rabbit] rabbit_port - [DEFAULT] rabbit_userid -> [oslo_messaging_rabbit] rabbit_userid - [DEFAULT] rabbit_password -> [oslo_messaging_rabbit] rabbit_password - [DEFAULT] rabbit_hosts -> [oslo_messaging_rabbit] rabbit_hosts - [DEFAULT] lock_path -> [oslo_concurrency] lock_path - [DEFAULT] enable_v1_api is now configurable. The default is true. This has been added because the v1 API is deprecated and will be removed in liberty. - [DEFAULT] enable_v2_api is now configurable. The default is true. policy.json - Update policy.json from icehouse default to kilo default version. This adds/modifies a number of rules and also updates the format of the file to the current version. api-paste.ini - Add the osprofiler filter. This file is now deployed using a template so that the hmac_keys configuration option can be set using the var cinder_profiler_hmac_key. - replace deprecated middleware with oslo_middleware versions. rootwrap.conf Updates the file to match kilo default. volume.filters Updates the file to match the kilo default. The volume_driver var has been updated to use the new LVM driver class. The signing_dir, /var/cache/cinder, permissions changed from 0755 to 0700 for fix warning by keystonemiddleware. Implements: blueprint master-kilofication Change-Id: I91f2385969568b18635bc534a98138d3dd5c5af2
87 lines
3.5 KiB
JSON
87 lines
3.5 KiB
JSON
{
|
|
"context_is_admin": "role:admin",
|
|
"admin_or_owner": "is_admin:True or project_id:%(project_id)s",
|
|
"default": "rule:admin_or_owner",
|
|
|
|
"admin_api": "is_admin:True",
|
|
|
|
"volume:create": "",
|
|
"volume:delete": "",
|
|
"volume:get": "",
|
|
"volume:get_all": "",
|
|
"volume:get_volume_metadata": "",
|
|
"volume:get_volume_admin_metadata": "rule:admin_api",
|
|
"volume:delete_volume_admin_metadata": "rule:admin_api",
|
|
"volume:update_volume_admin_metadata": "rule:admin_api",
|
|
"volume:get_snapshot": "",
|
|
"volume:get_all_snapshots": "",
|
|
"volume:extend": "",
|
|
"volume:update_readonly_flag": "",
|
|
"volume:retype": "",
|
|
|
|
"volume_extension:types_manage": "rule:admin_api",
|
|
"volume_extension:types_extra_specs": "rule:admin_api",
|
|
"volume_extension:volume_type_access": "",
|
|
"volume_extension:volume_type_access:addProjectAccess": "rule:admin_api",
|
|
"volume_extension:volume_type_access:removeProjectAccess": "rule:admin_api",
|
|
"volume_extension:volume_type_encryption": "rule:admin_api",
|
|
"volume_extension:volume_encryption_metadata": "rule:admin_or_owner",
|
|
"volume_extension:extended_snapshot_attributes": "",
|
|
"volume_extension:volume_image_metadata": "",
|
|
|
|
"volume_extension:quotas:show": "",
|
|
"volume_extension:quotas:update": "rule:admin_api",
|
|
"volume_extension:quota_classes": "",
|
|
|
|
"volume_extension:volume_admin_actions:reset_status": "rule:admin_api",
|
|
"volume_extension:snapshot_admin_actions:reset_status": "rule:admin_api",
|
|
"volume_extension:backup_admin_actions:reset_status": "rule:admin_api",
|
|
"volume_extension:volume_admin_actions:force_delete": "rule:admin_api",
|
|
"volume_extension:volume_admin_actions:force_detach": "rule:admin_api",
|
|
"volume_extension:snapshot_admin_actions:force_delete": "rule:admin_api",
|
|
"volume_extension:volume_admin_actions:migrate_volume": "rule:admin_api",
|
|
"volume_extension:volume_admin_actions:migrate_volume_completion": "rule:admin_api",
|
|
|
|
"volume_extension:volume_host_attribute": "rule:admin_api",
|
|
"volume_extension:volume_tenant_attribute": "rule:admin_or_owner",
|
|
"volume_extension:volume_mig_status_attribute": "rule:admin_api",
|
|
"volume_extension:hosts": "rule:admin_api",
|
|
"volume_extension:services": "rule:admin_api",
|
|
|
|
"volume_extension:volume_manage": "rule:admin_api",
|
|
"volume_extension:volume_unmanage": "rule:admin_api",
|
|
|
|
"volume:services": "rule:admin_api",
|
|
|
|
"volume:create_transfer": "",
|
|
"volume:accept_transfer": "",
|
|
"volume:delete_transfer": "",
|
|
"volume:get_all_transfers": "",
|
|
|
|
"volume_extension:replication:promote": "rule:admin_api",
|
|
"volume_extension:replication:reenable": "rule:admin_api",
|
|
|
|
"backup:create" : "",
|
|
"backup:delete": "",
|
|
"backup:get": "",
|
|
"backup:get_all": "",
|
|
"backup:restore": "",
|
|
"backup:backup-import": "rule:admin_api",
|
|
"backup:backup-export": "rule:admin_api",
|
|
|
|
"snapshot_extension:snapshot_actions:update_snapshot_status": "",
|
|
|
|
"consistencygroup:create" : "group:nobody",
|
|
"consistencygroup:delete": "group:nobody",
|
|
"consistencygroup:update": "group:nobody",
|
|
"consistencygroup:get": "group:nobody",
|
|
"consistencygroup:get_all": "group:nobody",
|
|
|
|
"consistencygroup:create_cgsnapshot" : "group:nobody",
|
|
"consistencygroup:delete_cgsnapshot": "group:nobody",
|
|
"consistencygroup:get_cgsnapshot": "group:nobody",
|
|
"consistencygroup:get_all_cgsnapshots": "group:nobody",
|
|
|
|
"scheduler_extension:scheduler_stats:get_pools" : "rule:admin_api"
|
|
}
|