Mailing List Archive

non public glance image can seen by all tenant
Hi,
I have setup rocky release at my openstack lab, now all of tenant (user)
can see non-public glance image create by another tenant (user)

here is my glance policy.json :

> {
> "context_is_admin": "role:admin",
> "default": "role:admin",
> "add_image": "",
> "delete_image": "",
> "get_image": "",
> "get_images": "",
> "modify_image": "",
> "publicize_image": "role:admin",
> "communitize_image": "",
> "copy_from": "",
> "download_image": "",
> "upload_image": "",
> "delete_image_location": "",
> "get_image_location": "",
> "set_image_location": "",
> "add_member": "",
> "delete_member": "",
> "get_member": "",
> "get_members": "",
> "modify_member": "",
> "manage_image_cache": "role:admin",
> "get_task": "",
> "get_tasks": "",
> "add_task": "",
> "modify_task": "",
> "tasks_api_access": "role:admin",
> "deactivate": "",
> "reactivate": "",
> "get_metadef_namespace": "",
> "get_metadef_namespaces":"",
> "modify_metadef_namespace":"",
> "add_metadef_namespace":"",
> "get_metadef_object":"",
> "get_metadef_objects":"",
> "modify_metadef_object":"",
> "add_metadef_object":"",
> "list_metadef_resource_types":"",
> "get_metadef_resource_type":"",
> "add_metadef_resource_type_association":"",
> "get_metadef_property":"",
> "get_metadef_properties":"",
> "modify_metadef_property":"",
> "add_metadef_property":"",
> "get_metadef_tag":"",
> "get_metadef_tags":"",
> "modify_metadef_tag":"",
> "add_metadef_tag":"",
> "add_metadef_tags":""
> }


any advice how to fix this ?


--
Cheers,



[image: --]
Adhi Priharmanto
[image: http://]about.me/a_dhi
<http://about.me/a_dhi?promo=email_sig>
Re: non public glance image can seen by all tenant [ In reply to ]
On 2018-10-26 11:29:27 +0700 (+0700), Adhi Priharmanto wrote:
> I have setup rocky release at my openstack lab, now all of tenant
> (user) can see non-public glance image create by another tenant
> (user)
[...]

This sounds very similar to https://launchpad.net/bugs/1799588 which
the Glance team has been asked to look into. See also the rather
lengthy troubleshooting discussion on the Operators ML starting
here:

http://lists.openstack.org/pipermail/openstack-operators/2018-October/016039.html

--
Jeremy Stanley
Re: non public glance image can seen by all tenant [ In reply to ]
Great,

Thanks Jeremy for pointing me in the right direction

On Fri, Oct 26, 2018 at 8:26 PM Jeremy Stanley <fungi@yuggoth.org> wrote:

> On 2018-10-26 11:29:27 +0700 (+0700), Adhi Priharmanto wrote:
> > I have setup rocky release at my openstack lab, now all of tenant
> > (user) can see non-public glance image create by another tenant
> > (user)
> [...]
>
> This sounds very similar to https://launchpad.net/bugs/1799588 which
> the Glance team has been asked to look into. See also the rather
> lengthy troubleshooting discussion on the Operators ML starting
> here:
>
>
> http://lists.openstack.org/pipermail/openstack-operators/2018-October/016039.html
>
> --
> Jeremy Stanley
> _______________________________________________
> Mailing list:
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack
> Post to : openstack@lists.openstack.org
> Unsubscribe :
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack
>


--
Cheers,



[image: --]
Adhi Priharmanto
[image: http://]about.me/a_dhi
<http://about.me/a_dhi?promo=email_sig>
+62-812-82121584