Juno - Juno - Juno - Juno - Juno - Juno - Juno - Juno -
Use the policy.json
file to define additional access controls
that apply to the OpenStack Networking service.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 | { "context_is_admin": " r o l e : a d m i n " , "admin_or_owner": " r u l e : c o n t e x t _ i s _ a d m i n o r t e n a n t _ i d : % ( t e n a n t _ i d ) s " , "admin_or_network_owner": " r u l e : c o n t e x t _ i s _ a d m i n o r t e n a n t _ i d : % ( n e t w o r k : t e n a n t _ i d ) s " , "admin_only": " r u l e : c o n t e x t _ i s _ a d m i n " , "regular_user": " " , "shared": " f i e l d : n e t w o r k s : s h a r e d = T r u e " , "shared_firewalls": " f i e l d : f i r e w a l l s : s h a r e d = T r u e " , "external": " f i e l d : n e t w o r k s : r o u t e r : e x t e r n a l = T r u e " , "default": " r u l e : a d m i n _ o r _ o w n e r " , "create_subnet": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "get_subnet": " r u l e : a d m i n _ o r _ o w n e r o r r u l e : s h a r e d " , "update_subnet": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "delete_subnet": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "create_network": " " , "get_network": " r u l e : a d m i n _ o r _ o w n e r o r r u l e : s h a r e d o r r u l e : e x t e r n a l " , "get_network:router:external": " r u l e : r e g u l a r _ u s e r " , "get_network:segments": " r u l e : a d m i n _ o n l y " , "get_network:provider:network_type": " r u l e : a d m i n _ o n l y " , "get_network:provider:physical_network": " r u l e : a d m i n _ o n l y " , "get_network:provider:segmentation_id": " r u l e : a d m i n _ o n l y " , "get_network:queue_id": " r u l e : a d m i n _ o n l y " , "create_network:shared": " r u l e : a d m i n _ o n l y " , "create_network:router:external": " r u l e : a d m i n _ o n l y " , "create_network:segments": " r u l e : a d m i n _ o n l y " , "create_network:provider:network_type": " r u l e : a d m i n _ o n l y " , "create_network:provider:physical_network": " r u l e : a d m i n _ o n l y " , "create_network:provider:segmentation_id": " r u l e : a d m i n _ o n l y " , "update_network": " r u l e : a d m i n _ o r _ o w n e r " , "update_network:segments": " r u l e : a d m i n _ o n l y " , "update_network:shared": " r u l e : a d m i n _ o n l y " , "update_network:provider:network_type": " r u l e : a d m i n _ o n l y " , "update_network:provider:physical_network": " r u l e : a d m i n _ o n l y " , "update_network:provider:segmentation_id": " r u l e : a d m i n _ o n l y " , "update_network:router:external": " r u l e : a d m i n _ o n l y " , "delete_network": " r u l e : a d m i n _ o r _ o w n e r " , "network_device": " f i e l d : p o r t : d e v i c e _ o w n e r = ~ ^ n e t w o r k : " , "create_port": " " , "create_port:device_owner": " n o t r u l e : n e t w o r k _ d e v i c e o r r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "create_port:mac_address": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "create_port:fixed_ips": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "create_port:port_security_enabled": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "create_port:binding:host_id": " r u l e : a d m i n _ o n l y " , "create_port:binding:profile": " r u l e : a d m i n _ o n l y " , "create_port:mac_learning_enabled": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "get_port": " r u l e : a d m i n _ o r _ o w n e r " , "get_port:queue_id": " r u l e : a d m i n _ o n l y " , "get_port:binding:vif_type": " r u l e : a d m i n _ o n l y " , "get_port:binding:vif_details": " r u l e : a d m i n _ o n l y " , "get_port:binding:host_id": " r u l e : a d m i n _ o n l y " , "get_port:binding:profile": " r u l e : a d m i n _ o n l y " , "update_port": " r u l e : a d m i n _ o r _ o w n e r " , "update_port:device_owner": " n o t r u l e : n e t w o r k _ d e v i c e o r r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "update_port:fixed_ips": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "update_port:port_security_enabled": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "update_port:binding:host_id": " r u l e : a d m i n _ o n l y " , "update_port:binding:profile": " r u l e : a d m i n _ o n l y " , "update_port:mac_learning_enabled": " r u l e : a d m i n _ o r _ n e t w o r k _ o w n e r " , "delete_port": " r u l e : a d m i n _ o r _ o w n e r " , "get_router:ha": " r u l e : a d m i n _ o n l y " , "create_router": " r u l e : r e g u l a r _ u s e r " , "create_router:external_gateway_info:enable_snat": " r u l e : a d m i n _ o n l y " , "create_router:distributed": " r u l e : a d m i n _ o n l y " , "create_router:ha": " r u l e : a d m i n _ o n l y " , "get_router": " r u l e : a d m i n _ o r _ o w n e r " , "get_router:distributed": " r u l e : a d m i n _ o n l y " , "update_router:external_gateway_info:enable_snat": " r u l e : a d m i n _ o n l y " , "update_router:distributed": " r u l e : a d m i n _ o n l y " , "update_router:ha": " r u l e : a d m i n _ o n l y " , "delete_router": " r u l e : a d m i n _ o r _ o w n e r " , "add_router_interface": " r u l e : a d m i n _ o r _ o w n e r " , "remove_router_interface": " r u l e : a d m i n _ o r _ o w n e r " , "create_firewall": " " , "get_firewall": " r u l e : a d m i n _ o r _ o w n e r " , "create_firewall:shared": " r u l e : a d m i n _ o n l y " , "get_firewall:shared": " r u l e : a d m i n _ o n l y " , "update_firewall": " r u l e : a d m i n _ o r _ o w n e r " , "update_firewall:shared": " r u l e : a d m i n _ o n l y " , "delete_firewall": " r u l e : a d m i n _ o r _ o w n e r " , "create_firewall_policy": " " , "get_firewall_policy": " r u l e : a d m i n _ o r _ o w n e r o r r u l e : s h a r e d _ f i r e w a l l s " , "create_firewall_policy:shared": " r u l e : a d m i n _ o r _ o w n e r " , "update_firewall_policy": " r u l e : a d m i n _ o r _ o w n e r " , "delete_firewall_policy": " r u l e : a d m i n _ o r _ o w n e r " , "create_firewall_rule": " " , "get_firewall_rule": " r u l e : a d m i n _ o r _ o w n e r o r r u l e : s h a r e d _ f i r e w a l l s " , "update_firewall_rule": " r u l e : a d m i n _ o r _ o w n e r " , "delete_firewall_rule": " r u l e : a d m i n _ o r _ o w n e r " , "create_qos_queue": " r u l e : a d m i n _ o n l y " , "get_qos_queue": " r u l e : a d m i n _ o n l y " , "update_agent": " r u l e : a d m i n _ o n l y " , "delete_agent": " r u l e : a d m i n _ o n l y " , "get_agent": " r u l e : a d m i n _ o n l y " , "create_dhcp-network": " r u l e : a d m i n _ o n l y " , "delete_dhcp-network": " r u l e : a d m i n _ o n l y " , "get_dhcp-networks": " r u l e : a d m i n _ o n l y " , "create_l3-router": " r u l e : a d m i n _ o n l y " , "delete_l3-router": " r u l e : a d m i n _ o n l y " , "get_l3-routers": " r u l e : a d m i n _ o n l y " , "get_dhcp-agents": " r u l e : a d m i n _ o n l y " , "get_l3-agents": " r u l e : a d m i n _ o n l y " , "get_loadbalancer-agent": " r u l e : a d m i n _ o n l y " , "get_loadbalancer-pools": " r u l e : a d m i n _ o n l y " , "create_floatingip": " r u l e : r e g u l a r _ u s e r " , "update_floatingip": " r u l e : a d m i n _ o r _ o w n e r " , "delete_floatingip": " r u l e : a d m i n _ o r _ o w n e r " , "get_floatingip": " r u l e : a d m i n _ o r _ o w n e r " , "create_network_profile": " r u l e : a d m i n _ o n l y " , "update_network_profile": " r u l e : a d m i n _ o n l y " , "delete_network_profile": " r u l e : a d m i n _ o n l y " , "get_network_profiles": " " , "get_network_profile": " " , "update_policy_profiles": " r u l e : a d m i n _ o n l y " , "get_policy_profiles": " " , "get_policy_profile": " " , "create_metering_label": " r u l e : a d m i n _ o n l y " , "delete_metering_label": " r u l e : a d m i n _ o n l y " , "get_metering_label": " r u l e : a d m i n _ o n l y " , "create_metering_label_rule": " r u l e : a d m i n _ o n l y " , "delete_metering_label_rule": " r u l e : a d m i n _ o n l y " , "get_metering_label_rule": " r u l e : a d m i n _ o n l y " , "get_service_provider": " r u l e : r e g u l a r _ u s e r " , "get_lsn": " r u l e : a d m i n _ o n l y " , "create_lsn": " r u l e : a d m i n _ o n l y " } |