[Openstack] project read-only role or create role with specific capabilities

Chengwei Yang chengwei.yang.cn at gmail.com
Thu Oct 19 07:15:39 UTC 2017


Hi list,

As I understand, keystone only defined two roles:

  - admin
  - non-admin, but can be any role name you want, role1, role2, user, _member_, whatever

say there are quite few people in the same project, so far, the users
assigned with the same role has exactly the same right to a project.

Is it possible to create a role with read-only capabilities with all
resources in a project?

If so, any hints?

In addition, I'd like to create a role which isn't admin but can manage
projects(create project, delete his project, manage project members and
etc.)

thanks in advance!

-- 
Thanks,
Chengwei
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: not available
URL: <http://lists.openstack.org/pipermail/openstack/attachments/20171019/e361f4eb/attachment.sig>


More information about the Openstack mailing list