Re: [Openstack-operators] Granular roles and policy.json modifications

2016-02-04 Thread Michael Richardson
> On 04/02/16 05:51, Michael Richardson wrote: >> Hi all, >> >> Is anyone using granular roles or groups, with fewer permissions granted >> than >> _member_ ? If so, have you found a nice, simple (within the context of >> OpenStack) method or scheme for:- >> >> a) modifying the default "admin_or_o

[Openstack-operators] Help with horizon and v3 auth

2016-02-04 Thread Abel Lopez
Hey everyone, In my liberty testing, I've got keystone v3 setup, and everything seems to work, except certain cinder functions Using openstack client, I can boot an instance from image to a new volume. Using horizon, this fails. I have followed the v3 guides, having setup local_settings to have

Re: [Openstack-operators] DVR and public IP consumption

2016-02-04 Thread Tomas Vondra
Carl Baldwin writes: > You're right, the IP in the fip namespace doesn't ever get written in > to any packets or used as an arp destination. It is currently > meaningless. That will change with BGP's capability to routed DVR > traffic in Mitaka because that IP will be used as a next hop. > Howe

Re: [Openstack-operators] Draft Agenda for MAN Ops Meetup (Feb 15, 16)

2016-02-04 Thread Tom Fifield
Hi all, We still need moderators for the following: * Upgrade challenges, LTS releases, patches and packaging * Keystone Federation - discussion session * Post-Puppet deployment patterns - discussion * HA at the Hypervisor level * OSOps - what is it, where is it going, what you can do * OSOps wo

Re: [Openstack-operators] Granular roles and policy.json modifications

2016-02-04 Thread Tom Fifield
On 04/02/16 05:51, Michael Richardson wrote: Hi all, Is anyone using granular roles or groups, with fewer permissions granted than _member_ ? If so, have you found a nice, simple (within the context of OpenStack) method or scheme for:- a) modifying the default "admin_or_owner" rules, which woul