[Openstack] [Metering] External API definition

Nick Barcet nick.barcet at canonical.com
Wed May 9 15:48:40 UTC 2012


On 05/09/2012 08:36 AM, Doug Hellmann wrote:
> 
> 
> On Tue, May 8, 2012 at 8:43 PM, Nick Barcet <nick.barcet at canonical.com
> <mailto:nick.barcet at canonical.com>> wrote:
> 
>     On 05/08/2012 11:39 AM, Doug Hellmann wrote:
>     [..]
>     >     * Requests must be authenticated (separate from keystone, or
>     only linked
>     >     to accounting type account)
>     >
>     >
>     > What is the motivation for authenticating with a service other than
>     > keystone?
> 
>     The only thing I am trying to express here is that that profiles that
>     have access to other OpenStack components should not necessarily have
>     access to metering information.  This information should be accessible
>     only a few select users which group may or may not intersect with users
>     stored in Keystone already.
> 
> 
> I see. Is it enough to say that the API is meant for "admin" users only,
> or does that still imply more access than we want to grant?

I don't see the point to try to restrict admins from this, as it would
be mostly pointless in the end, but I do see the need to define a type
of account which only right is to consult this information without any
other privilege.

Nick


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 900 bytes
Desc: OpenPGP digital signature
URL: <http://lists.openstack.org/pipermail/openstack/attachments/20120509/98ad011c/attachment.sig>


More information about the Openstack mailing list