HI

As the number of configuration options increases and OpenStack installations 
become more complex, the chances of incorrect configuration increases. There is 
no better way of enabling cloud providers to be able to check the configuration 
state of an OpenStack service than providing a direct REST API that allows the 
current running values to be inspected. Having an API to provide this 
information becomes increasingly important for dev/ops style operation.

As part of Keystone we are considering adding such an ability (see: 
https://review.openstack.org/#/c/106558/).  However, since this is the sort of 
thing that might be relevant to and/or affect other projects, I wanted to get 
views from the wider dev audience.  

Any such change obviously has to take security in mind - and as the spec says, 
just like when we log config options, any options marked as secret will be 
obfuscated.  In addition, the API will be protected by the normal policy 
mechanism and is likely in most installations to be left as "admin required".  
And of course, since it is an extension, if a particular installation does not 
want to use it, they don't need to load it.

Do people think this is a good idea?  Useful in other projects?  Concerned 
about the risks?

Henry

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail

_______________________________________________
OpenStack-dev mailing list
[email protected]
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev

Reply via email to