[openstack-dev] Search Project - summit follow up
Dmitri Zimin(e) | StackStorm
dz at stackstorm.com
Wed Nov 20 19:06:02 UTC 2013
Thanks Terry for highlighting this:
Yes, tenant isolation is the must. It's not reflected in the prototype - it
queries Solr directly; but the proper implementation will go through the
query API service, where ACL will be applied.
UX folks are welcome to comment on expected queries.
I think the key benefit of cross-resource index over querying DBs is that
it saves the clients from implementing complex queries case by case,
leaving flexibility to the user.
-- Dmitri.
On Wed, Nov 20, 2013 at 2:27 AM, Thierry Carrez <thierry at openstack.org>wrote:
> Dmitri Zimin(e) | StackStorm wrote:
> > Hi Stackers,
> >
> > The project Search is a service providing fast full-text search for
> > resources across OpenStack services.
> > [...]
>
> At first glance this looks slightly scary from a security / tenant
> isolation perspective. Most search results would be extremely
> user-specific (and leaking data from one user to another would be
> catastrophic), so the benefits of indexing (vs. querying DB) would be
> very limited ?
>
> --
> Thierry Carrez (ttx)
>
> _______________________________________________
> OpenStack-dev mailing list
> OpenStack-dev at lists.openstack.org
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20131120/4bcf1105/attachment.html>
More information about the OpenStack-dev
mailing list