[aodh][keystone] handling of webhook / alarm authentication

info at dantalion.nl info at dantalion.nl
Fri Jan 10 09:28:19 UTC 2020


Hello,

I was wondering how a service receiving an aodh webhook could perform
authentication?

The documentation describes the webhook as a simple post-request so I
was wondering if a keystone token context is available when these
requests are received?

If not, I was wondering if anyone had any recommendation on how to
perform authentication upon received post-requests?

So far I have come up with limiting the functionality of these webhooks
such as rate-limiting and administrators having to explicitly enable
these webhooks before they work.

Hope anyone else could provide further valuable information.

Kind regards,
Corne Lukken
Watcher core-reviewer



More information about the openstack-discuss mailing list