Re: [Openstack-operators] Granular roles and policy.json modifications

2016-02-04 Thread Michael Richardson
> On 04/02/16 05:51, Michael Richardson wrote: >> Hi all, >> >> Is anyone using granular roles or groups, with fewer permissions granted >> than >> _member_ ? If so, have you found a nice, simple (within the context of >> OpenStack) method or scheme for:- >> >> a) modifying the default "admin_or_o

Re: [Openstack-operators] Granular roles and policy.json modifications

2016-02-04 Thread Tom Fifield
On 04/02/16 05:51, Michael Richardson wrote: Hi all, Is anyone using granular roles or groups, with fewer permissions granted than _member_ ? If so, have you found a nice, simple (within the context of OpenStack) method or scheme for:- a) modifying the default "admin_or_owner" rules, which woul

[Openstack-operators] Granular roles and policy.json modifications

2016-02-03 Thread Michael Richardson
Hi all, Is anyone using granular roles or groups, with fewer permissions granted than _member_ ? If so, have you found a nice, simple (within the context of OpenStack) method or scheme for:- a) modifying the default "admin_or_owner" rules, which would otherwise match any role as long as the te