29 May
2025
29 May
'25
10:41 a.m.
Hello, Thanks a lot for your quick response. I used my role for 1. "os_compute_api:servers:detail:get_all_tenants": "(rule:context_is_admin) or (role:myrole)" -- it works! 2. "os_compute_api:servers:index:get_all_tenants": "(rule:context_is_admin) or (role:myrole)" -- it works! 3. "os_compute_api:servers:allow_all_filters": "(rule:context_is_admin) or (role:myrole)" -- it works! 4. "os_compute_api:servers:show": "rule:project_reader_or_admin or role:myrole" -- it does not work ( All of these four targets has "Intended scope(s): project" due to oslo policy-sample-generator utility output. Could you please suggest where to get extra info of limitations for different nova and keystone targets? DB triggers?