The following is an overview of all available policies in Designate. For a sample configuration file, refer to policy.yaml.
admin
Default: | role:admin or is_admin:True |
---|
(no description provided)
primary_zone
Default: | target.zone_type:SECONDARY |
---|
(no description provided)
owner
Default: | tenant:%(tenant_id)s |
---|
(no description provided)
admin_or_owner
Default: | rule:admin or rule:owner |
---|
(no description provided)
default
Default: | rule:admin_or_owner |
---|
(no description provided)
target
Default: | tenant:%(target_tenant_id)s |
---|
(no description provided)
owner_or_target
Default: | rule:target or rule:owner |
---|
(no description provided)
admin_or_owner_or_target
Default: | rule:owner_or_target or rule:admin |
---|
(no description provided)
admin_or_target
Default: | rule:admin or rule:target |
---|
(no description provided)
zone_primary_or_admin
Default: | ('PRIMARY':%(zone_type)s and rule:admin_or_owner) OR ('SECONDARY':%(zone_type)s AND is_admin:True) |
---|
(no description provided)
create_blacklist
Default: |
|
---|---|
Operations: |
|
Create blacklist.
find_blacklist
Default: |
|
---|---|
Operations: |
|
Find blacklist.
find_blacklists
Default: |
|
---|---|
Operations: |
|
Find blacklists.
get_blacklist
Default: |
|
---|---|
Operations: |
|
Get blacklist.
update_blacklist
Default: |
|
---|---|
Operations: |
|
Update blacklist.
delete_blacklist
Default: |
|
---|---|
Operations: |
|
Delete blacklist.
use_blacklisted_zone
Default: |
|
---|---|
Operations: |
|
Allowed bypass the blacklist.
all_tenants
Default: | rule:admin |
---|
Action on all tenants.
edit_managed_records
Default: | rule:admin |
---|
Edit managed records.
use_low_ttl
Default: | rule:admin |
---|
Use low TTL.
use_sudo
Default: | rule:admin |
---|
Accept sudo from user to tenant.
diagnostics_ping
Default: | rule:admin |
---|
Diagnose ping.
diagnostics_sync_zones
Default: | rule:admin |
---|
Diagnose sync zones.
diagnostics_sync_zone
Default: | rule:admin |
---|
Diagnose sync zone.
diagnostics_sync_record
Default: | rule:admin |
---|
Diagnose sync record.
create_pool
Default: | rule:admin |
---|
Create pool.
find_pools
Default: |
|
---|---|
Operations: |
|
Find pool.
find_pool
Default: |
|
---|---|
Operations: |
|
Find pools.
get_pool
Default: |
|
---|---|
Operations: |
|
Get pool.
update_pool
Default: | rule:admin |
---|
Update pool.
delete_pool
Default: | rule:admin |
---|
Delete pool.
zone_create_forced_pool
Default: |
|
---|---|
Operations: |
|
load and set the pool to the one provided in the Zone attributes.
get_quotas
Default: |
|
---|---|
Operations: |
|
View Current Project’s Quotas.
get_quota
Default: | rule:admin_or_owner |
---|
(no description provided)
set_quota
Default: |
|
---|---|
Operations: |
|
Set Quotas.
reset_quotas
Default: |
|
---|---|
Operations: |
|
Reset Quotas.
find_records
Default: |
|
---|---|
Operations: |
|
Find records.
count_records
Default: | rule:admin_or_owner |
---|
(no description provided)
create_recordset
Default: |
|
---|---|
Operations: |
|
Create Recordset
get_recordsets
Default: | rule:admin_or_owner |
---|
(no description provided)
get_recordset
Default: |
|
---|---|
Operations: |
|
Get recordset
update_recordset
Default: |
|
---|---|
Operations: |
|
Update recordset
delete_recordset
Default: |
|
---|---|
Operations: |
|
Delete RecordSet
count_recordset
Default: | rule:admin_or_owner |
---|
Count recordsets
find_service_status
Default: |
|
---|---|
Operations: |
|
Find a single Service Status
find_service_statuses
Default: |
|
---|---|
Operations: |
|
List service statuses.
update_service_status
Default: | rule:admin |
---|
(no description provided)
find_tenants
Default: | rule:admin |
---|
Find all Tenants.
get_tenant
Default: | rule:admin |
---|
Get all Tenants.
count_tenants
Default: | rule:admin |
---|
Count tenants
create_tld
Default: |
|
---|---|
Operations: |
|
Create Tld
find_tlds
Default: |
|
---|---|
Operations: |
|
List Tlds
get_tld
Default: |
|
---|---|
Operations: |
|
Show Tld
update_tld
Default: |
|
---|---|
Operations: |
|
Update Tld
delete_tld
Default: |
|
---|---|
Operations: |
|
Delete Tld
create_tsigkey
Default: |
|
---|---|
Operations: |
|
Create Tsigkey
find_tsigkeys
Default: |
|
---|---|
Operations: |
|
List Tsigkeys
get_tsigkey
Default: |
|
---|---|
Operations: |
|
Show a Tsigkey
update_tsigkey
Default: |
|
---|---|
Operations: |
|
Update Tsigkey
delete_tsigkey
Default: |
|
---|---|
Operations: |
|
Delete a Tsigkey
create_zone
Default: |
|
---|---|
Operations: |
|
Create Zone
get_zones
Default: | rule:admin_or_owner |
---|
(no description provided)
get_zone
Default: |
|
---|---|
Operations: |
|
Get Zone
get_zone_servers
Default: | rule:admin_or_owner |
---|
(no description provided)
find_zones
Default: |
|
---|---|
Operations: |
|
List existing zones
update_zone
Default: |
|
---|---|
Operations: |
|
Update Zone
delete_zone
Default: |
|
---|---|
Operations: |
|
Delete Zone
xfr_zone
Default: |
|
---|---|
Operations: |
|
Manually Trigger an Update of a Secondary Zone
abandon_zone
Default: |
|
---|---|
Operations: |
|
Abandon Zone
count_zones
Default: | rule:admin_or_owner |
---|
(no description provided)
count_zones_pending_notify
Default: | rule:admin_or_owner |
---|
(no description provided)
purge_zones
Default: | rule:admin |
---|
(no description provided)
touch_zone
Default: | rule:admin_or_owner |
---|
(no description provided)
zone_export
Default: |
|
---|---|
Operations: |
|
Retrive a Zone Export from the Designate Datastore
create_zone_export
Default: |
|
---|---|
Operations: |
|
Create Zone Export
find_zone_exports
Default: |
|
---|---|
Operations: |
|
List Zone Exports
get_zone_export
Default: |
|
---|---|
Operations: |
|
Get Zone Exports
update_zone_export
Default: |
|
---|---|
Operations: |
|
Update Zone Exports
create_zone_import
Default: |
|
---|---|
Operations: |
|
Create Zone Import
find_zone_imports
Default: |
|
---|---|
Operations: |
|
List all Zone Imports
get_zone_import
Default: |
|
---|---|
Operations: |
|
Get Zone Imports
update_zone_import
Default: |
|
---|---|
Operations: |
|
Update Zone Imports
delete_zone_import
Default: |
|
---|---|
Operations: |
|
Delete a Zone Import
create_zone_transfer_accept
Default: |
|
---|---|
Operations: |
|
Create Zone Transfer Accept
get_zone_transfer_accept
Default: |
|
---|---|
Operations: |
|
Get Zone Transfer Accept
find_zone_transfer_accepts
Default: |
|
---|---|
Operations: |
|
List Zone Transfer Accepts
find_zone_transfer_accept
Default: | rule:admin |
---|
(no description provided)
update_zone_transfer_accept
Default: |
|
---|---|
Operations: |
|
Update a Zone Transfer Accept
delete_zone_transfer_accept
Default: | rule:admin |
---|
(no description provided)
create_zone_transfer_request
Default: |
|
---|---|
Operations: |
|
Create Zone Transfer Accept
get_zone_transfer_request
Default: |
|
---|---|
Operations: |
|
Show a Zone Transfer Request
get_zone_transfer_request_detailed
Default: | rule:admin_or_owner |
---|
(no description provided)
find_zone_transfer_requests
Default: |
|
---|---|
Operations: |
|
List Zone Transfer Requests
find_zone_transfer_request
Default: | @ |
---|
(no description provided)
update_zone_transfer_request
Default: |
|
---|---|
Operations: |
|
Update a Zone Transfer Request
delete_zone_transfer_request
Default: |
|
---|---|
Operations: |
|
Delete a Zone Transfer Request
Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.