Browse Source

Allow to configure policy_dirs

This patch makes it possible to override the current service default,
which is /etc/<service>/policy.d .

Change-Id: I006c137e78c1bac99202ced38fd6f82a07ad65e3
changes/09/785809/1
Thomas Goirand 2 months ago
parent
commit
478293eedc
3 changed files with 14 additions and 1 deletions
  1. +7
    -1
      manifests/policy.pp
  2. +5
    -0
      releasenotes/notes/policy-dirs-6ee9bf5a0f434aad.yaml
  3. +2
    -0
      spec/classes/tacker_policy_spec.rb

+ 7
- 1
manifests/policy.pp View File

@ -32,11 +32,16 @@
# (Optional) Path to the tacker policy.yaml file
# Defaults to /etc/tacker/policy.yaml
#
# [*policy_dirs*]
# (Optional) Path to the tacker policy folder
# Defaults to $::os_service_default
#
class tacker::policy (
$enforce_scope = $::os_service_default,
$enforce_new_defaults = $::os_service_default,
$policies = {},
$policy_path = '/etc/tacker/policy.yaml',
$policy_dirs = $::os_service_default,
) {
include tacker::deps
@ -56,7 +61,8 @@ class tacker::policy (
oslo::policy { 'tacker_config':
enforce_scope => $enforce_scope,
enforce_new_defaults => $enforce_new_defaults,
policy_file => $policy_path
policy_file => $policy_path,
policy_dirs => $policy_dirs,
}
}

+ 5
- 0
releasenotes/notes/policy-dirs-6ee9bf5a0f434aad.yaml View File

@ -0,0 +1,5 @@
---
features:
- |
There is now a new policy_dirs parameter in the tacker::policy class,
so one can set a custom path.

+ 2
- 0
spec/classes/tacker_policy_spec.rb View File

@ -7,6 +7,7 @@ describe 'tacker::policy' do
:enforce_scope => false,
:enforce_new_defaults => false,
:policy_path => '/etc/tacker/policy.yaml',
:policy_dirs => '/etc/tacker/policy.d',
:policies => {
'context_is_admin' => {
'key' => 'context_is_admin',
@ -28,6 +29,7 @@ describe 'tacker::policy' do
:enforce_scope => false,
:enforce_new_defaults => false,
:policy_file => '/etc/tacker/policy.yaml',
:policy_dirs => '/etc/tacker/policy.d',
)
end
end


Loading…
Cancel
Save