Re: [openstack-dev] [Neutron] Security Worries about Network RBAC

2017-03-02 Thread Adrian Turjak
Bug/RFE is up! https://bugs.launchpad.net/neutron/+bug/1669630 Hopefully that sums of what I'm ideally after well enough, and is useful to the greater community and project as a whole. Cheers, Adrian Turjak On 01/03/17 22:00, Adrian Turjak wrote: > Hello Kevin, > > Thanks for the prompt

Re: [openstack-dev] [Neutron] Security Worries about Network RBAC

2017-03-01 Thread Adrian Turjak
Hello Kevin,Thanks for the prompt response! This is fantastic. I'll throw up a blueprint together tomorrow.Backwards compatibility is the biggest issue, as anyone currently using the feature and assuming no approval step is going to be hit by it. The only sensible solution I can see being easy to

Re: [openstack-dev] [Neutron] Security Worries about Network RBAC

2017-03-01 Thread Kevin Benton
Hi Adrian, Thanks for the write-up. I think adding an approval workflow to Neutron is a reasonable feature request. It probably wouldn't be back-portable because it's going to require an API change and a new column in the database for approval state so you would have to patch it in manually in

[openstack-dev] [Neutron] Security Worries about Network RBAC

2017-02-28 Thread Adrian Turjak
Hello Openstack-Devs, I'm just trying to find out if there is any proposed work to make the network RBAC a bit safer. For context, I'm part of a company running a public cloud and we would like to expose Network RBAC to customers who have multiple projects so that they can share networks between