Re: IAM Plugin

2017-09-15 Thread Rafael Weingärtner
ly the use of role base access control model where you > link > > "permission"(api methods) to roles and then roles to users. > > > > On Thu, Sep 14, 2017 at 9:35 AM, Voloshanenko Igor < > > igor.voloshane...@gmail.com> wrote: > > > > > Hi, fo

Re: IAM Plugin

2017-09-14 Thread Voloshanenko Igor
m> wrote: > > > Hi, folks! > > > > Can I kindly ask you about help with IAM plugin? > > > > I'm trying to test it - and don;t see any relative instruction - how to > > install it (both plugin and server) sides and any API examples... > > >

Re: IAM Plugin

2017-09-14 Thread Rafael Weingärtner
te: > Hi, folks! > > Can I kindly ask you about help with IAM plugin? > > I'm trying to test it - and don;t see any relative instruction - how to > install it (both plugin and server) sides and any API examples... > > I found only 2 presentations and one jira tick

IAM Plugin

2017-09-14 Thread Voloshanenko Igor
Hi, folks! Can I kindly ask you about help with IAM plugin? I'm trying to test it - and don;t see any relative instruction - how to install it (both plugin and server) sides and any API examples... I found only 2 presentations and one jira ticket which looks like outdated ((( tnx in ad

RE: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread Prachi Damle
-Original Message- From: sebgoa [mailto:run...@gmail.com] Sent: Wednesday, January 22, 2014 12:41 AM To: dev@cloudstack.apache.org Subject: Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920) On Jan 21, 2014, at 10:57 PM, Prachi Damle wrote: > Min and myself would like

RE: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread Prachi Damle
-Original Message- From: Min Chen [mailto:min.c...@citrix.com] Sent: Wednesday, January 22, 2014 10:16 AM To: dev@cloudstack.apache.org Subject: Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920) Hi Rajani, See my answers in line. Thanks On 1/22/14 6:29 AM

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread Min Chen
phase 2, we may consider figuring out a way to categorize APIs to that level. > > >- >Thanks, >Rajani > >From: Prachi Damle [prachi.da...@citrix.com] >Sent: Wednesday, January 22, 2014 3:27 AM >To: dev@cloudstack.apache.org >Su

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread Min Chen
Hi Koushik, See my answers in line. Thanks. -min On 1/22/14 12:30 AM, "Koushik Das" wrote: >Some questions: > >- Is there a concept of generic permission (any action, any resource >etc.)? There shouldn't be a need to define hundreds of explicit >permissions for admin ac

RE: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread Rajani Karuturi
ch of control and information to save. - Thanks, Rajani From: Prachi Damle [prachi.da...@citrix.com] Sent: Wednesday, January 22, 2014 3:27 AM To: dev@cloudstack.apache.org Subject: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920) Min and myself

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread sebgoa
On Jan 21, 2014, at 10:57 PM, Prachi Damle wrote: > Min and myself would like to propose an identity and access management plugin > for CloudStack for the ACS 4.4 release. > > Here is the functional spec we have drafted for the first phase: > https://cwiki.apache.org/confluence/display/CLOUDST

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-22 Thread Koushik Das
Some questions: - Is there a concept of generic permission (any action, any resource etc.)? There shouldn't be a need to define hundreds of explicit permissions for admin account. - I think it would be good to have a notion of parent policy. This will avoid duplication of permissions. - Can you

RE: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-21 Thread Prachi Damle
-Original Message- From: Chiradeep Vittal [mailto:chiradeep.vit...@citrix.com] Sent: Tuesday, January 21, 2014 4:27 PM To: dev@cloudstack.apache.org Subject: Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920) Also not clear on how the dedicateXyZ problem is being solved in

RE: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-21 Thread Prachi Damle
Some answers inline. Prachi -Original Message- From: Chiradeep Vittal [mailto:chiradeep.vit...@citrix.com] Sent: Tuesday, January 21, 2014 4:20 PM To: dev@cloudstack.apache.org Subject: Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920) SAML 2.0 is not precluded with this

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-21 Thread Chiradeep Vittal
Also not clear on how the dedicateXyZ problem is being solved in Phase1 (or not). Can I (end user) create a VPC and allow user Bob to create VMs in my VPC? On 1/21/14 4:20 PM, "Chiradeep Vittal" wrote: >SAML 2.0 is not precluded with this design, it seems. >I found the FS both confusing and illu

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-21 Thread Chiradeep Vittal
SAML 2.0 is not precluded with this design, it seems. I found the FS both confusing and illuminating. I think what confuses me is the interchange of 'acl', 'iam' and 'policy'. Especially since ACL is used in the networking context. IMO, renaming the tables and APIs to not use ACL but IAM would cla

Re: [Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-21 Thread Erik Weber
On Tue, Jan 21, 2014 at 10:57 PM, Prachi Damle wrote: > Min and myself would like to propose an identity and access management > plugin for CloudStack for the ACS 4.4 release. > > Here is the functional spec we have drafted for the first phase: > > https://cwiki.apache.org/confluence/display/CLOUD

[Proposal]CloudStack IAM plugin feature (CLOUDSTACK-5920)

2014-01-21 Thread Prachi Damle
Min and myself would like to propose an identity and access management plugin for CloudStack for the ACS 4.4 release. Here is the functional spec we have drafted for the first phase: https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+Identity+and+Access+Management+%28IAM%29+Plugin