Re: [Openstack] Authorization Question

2013-03-04 Thread Nathanael Burton
Dolph, In our deployments we often want to restrict projects to particular endpoints or regions. We've currently hacked that in to our Folsom systems by adding a 'regions' list to the 'extra' column of the tenant table. With only a few minor tweaks to keystone to return the filtered service cata

Re: [Openstack] Authorization Question

2013-03-04 Thread Miller, Mark M (EB SW Cloud - R&D - Corvallis)
Corvallis) Subject: Re: [Openstack] Authorization Question That's correct. Right now, all endpoints registered in keystone are returned to all users, regardless of whether they actually have any sort of authorization on those endpoints. I suspect we'll be having a planning session at the de

Re: [Openstack] Authorization Question

2013-03-04 Thread Dolph Mathews
That's correct. Right now, all endpoints registered in keystone are returned to all users, regardless of whether they actually have any sort of authorization on those endpoints. I suspect we'll be having a planning session at the design summit on this topic -- I'd be helpful to better understand y

[Openstack] Authorization Question

2013-03-04 Thread Miller, Mark M (EB SW Cloud - R&D - Corvallis)
Hello, I have been looking over the Keystone v3 API documentation as well as the database table columns. My question concerns endpoint access restrictions. I don't see any noticeable way to associate endpoints with domains which means that any user can access any endpoint of any domain. Is this