Wednesday, 2025-07-16

manumohhey .. I am a bit confused about how role "user" is being used inside openstack. I have a tenant with role "user" and when I try to  perform a glance image from horizon it throws 403 but cli works fine .  Upon checking the glance policy I see only reference to reader/member/admin but not user https://github.com/openstack/glance/blob/master/glance/policies/base.py.   12:01
gtemathe role "user" is not anything standard upstream12:02
manumohI am still on wallaby12:02
gtemaI do not remember it ever existed 12:02
manumohwonder how its working as I don't have any custom policy and the default policy is moved into the code instead of policy.json . 12:05
manumohi'll dig deep .. @gtema thanks for the response12:05
gtemawlcm. Maybe you had it as custom some years ago12:06
manumohif thats the case during the upgrades it will carry somewhere other than policy fiel12:07
gtemaonce you created role in keystone and assigned it to the user - it will persist through upgrades12:07
gtemabut role in keystone is just a role. Services themselves give a meaning to the role12:08
gtemakeystone on its own is not implementing/tracking policies for the roles12:08
manumohok12:15

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!