)]}'
{"id":"openstack%2Fkeystone~771509","triplet_id":"openstack%2Fkeystone~master~Iea28faf1b3e63c7ab07e90808d2bc76ee3ee0612","project":"openstack/keystone","branch":"master","topic":"secure-rbac","hashtags":[],"change_id":"Iea28faf1b3e63c7ab07e90808d2bc76ee3ee0612","subject":"Clarify ``reader`` role implementation in persona admin guide","status":"MERGED","created":"2021-01-19 19:40:11.000000000","updated":"2021-02-27 05:24:57.000000000","submitted":"2021-02-27 05:23:02.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":17,"unresolved_comment_count":1,"has_review_started":true,"submission_id":"771509-secure-rbac","meta_rev_id":"ba972fbe7ad44b98a00c1a78ecfe0c6f3dace0b4","_number":771509,"virtual_id_number":771509,"owner":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"},{"value":0,"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2021-02-27 05:23:01.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"all":[{"value":2,"date":"2021-02-23 14:48:34.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":1,"date":"2021-02-26 06:32:04.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"},{"value":1,"date":"2021-02-05 15:19:14.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},{"value":2,"date":"2021-02-27 03:57:58.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"all":[{"value":0,"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"},{"value":0,"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},{"value":1,"date":"2021-02-27 03:57:58.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[{"_account_id":20813,"name":"Sofia Enriquez","email":"lsofia.enriquez@gmail.com","username":"enriquetaso"}],"reviewers":{"REVIEWER":[{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"_account_id":20813,"name":"Sofia Enriquez","email":"lsofia.enriquez@gmail.com","username":"enriquetaso"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-01-20 03:37:35.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-01-21 19:11:12.000000000","updated_by":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"reviewer":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"state":"REVIEWER"},{"updated":"2021-01-27 13:26:54.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"state":"REVIEWER"},{"updated":"2021-01-27 13:26:54.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"state":"REVIEWER"},{"updated":"2021-01-27 14:49:28.000000000","updated_by":{"_account_id":20813,"name":"Sofia Enriquez","email":"lsofia.enriquez@gmail.com","username":"enriquetaso"},"reviewer":{"_account_id":20813,"name":"Sofia Enriquez","email":"lsofia.enriquez@gmail.com","username":"enriquetaso"},"state":"REVIEWER"},{"updated":"2021-02-01 15:26:58.000000000","updated_by":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"reviewer":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"state":"REVIEWER"},{"updated":"2021-02-26 06:32:04.000000000","updated_by":{"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"},"reviewer":{"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"},"state":"REVIEWER"}],"messages":[{"id":"ba7cbf2cb549f11b1d347573152fc2e64bd528cb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-01-19 19:40:11.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"c392ff5558919d22c63ef7a2e082e60f69f21886","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-01-19 19:40:35.000000000","message":"Topic set to secure-rbac","accounts_in_message":[],"_revision_number":1},{"id":"2649a451079b37dd5c70653b4ff7f71fa14389e5","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-01-20 03:37:35.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/754c31c09ba44f669c034fbec805d502 : SUCCESS in 5m 58s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/52764783b054419ba31af7d8d1422269 : SUCCESS in 12m 09s","accounts_in_message":[],"_revision_number":1},{"id":"627dcad6a3772c1f9bf217dda23f2dd19ce64eec","author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"date":"2021-01-21 19:11:12.000000000","message":"Patch Set 1: Code-Review+1\n\n(1 comment)\n\nlgtm, nice info.","accounts_in_message":[],"_revision_number":1},{"id":"8e87cf4747092d3d3c78f96ed897b1da58d56310","author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"date":"2021-02-01 15:26:58.000000000","message":"Patch Set 1: Code-Review+1\n\n(5 comments)\n\nThanks for clarifying this!","accounts_in_message":[],"_revision_number":1},{"id":"5364d1e1f331140def7d12bb2d9b27deda2bac6e","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-01 19:24:26.000000000","message":"Patch Set 1:\n\n(3 comments)","accounts_in_message":[],"_revision_number":1},{"id":"d0fe81ef0bc5408ce79a13d6b8f68b73e4cbcdf4","author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"date":"2021-02-04 17:18:52.000000000","message":"Patch Set 1:\n\n(2 comments)","accounts_in_message":[],"_revision_number":1},{"id":"7818283196bd5ec7c66557a171e7c86cf6432445","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-05 14:28:01.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"d90695f639e2c27c563f4c7073f54b2ab13b51f9","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-05 14:28:13.000000000","message":"Patch Set 2:\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"c302246802a449020880086e73fd4f4b9811980c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-05 14:32:27.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"57624fe72a81b0147ab0b9ea81944768833d05ad","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-05 14:32:35.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"03c5c4371112fda86a0b33e07949e5e5debdb2b7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-02-05 14:55:27.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/7de1475506374b0ba5914c4ed58e7a37 : SUCCESS in 7m 08s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/12900fd81b594530959efc3e31d062a8 : SUCCESS in 15m 18s","accounts_in_message":[],"_revision_number":3},{"id":"b680bb05c3ef27f2175121727534ddd045dca85c","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-05 14:59:15.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"062e313aa78ada1fa5067cc0f5e6e28cfbbaf914","author":{"_account_id":6618,"name":"Ruby Loo","email":"opensrloo@gmail.com","username":"rloo"},"date":"2021-02-05 15:19:14.000000000","message":"Patch Set 3: Code-Review+1\n\nThanks!","accounts_in_message":[],"_revision_number":3},{"id":"923ba45c58aa27128f384874130d1cb50ca14c97","author":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"date":"2021-02-09 17:47:58.000000000","message":"Patch Set 3:\n\nWhat are some examples of sensitive information useful to auditors but not accessible through the reader role?","accounts_in_message":[],"_revision_number":3},{"id":"2022fbd2d6b66476a14d1faff00f5857fa5f87b6","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-02-10 17:48:41.000000000","message":"Patch Set 3:\n\n\u003e Patch Set 3:\n\u003e \n\u003e What are some examples of sensitive information useful to auditors but not accessible through the reader role?\n\nOne example the glance folks shared with me was license keys \n\nhttps://review.opendev.org/c/openstack/keystone/+/771509/3/doc/source/admin/service-api-protection.rst#96","accounts_in_message":[],"_revision_number":3},{"id":"618c4451a863dd20ea8a40ec091cc230d075e523","author":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"date":"2021-02-23 14:48:34.000000000","message":"Patch Set 3: Code-Review+2","accounts_in_message":[],"_revision_number":3},{"id":"7616539be1dc1fe72350e442a5e5146373e8fddb","author":{"_account_id":32291,"name":"wushiming","email":"wushiming@yovole.com","username":"wushiming"},"date":"2021-02-26 06:32:04.000000000","message":"Patch Set 3: Code-Review+1","accounts_in_message":[],"_revision_number":3},{"id":"88815d1ae19595d0e01b0002dbae3df0b1da203b","author":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"date":"2021-02-27 03:57:58.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":3},{"id":"95d55de81304390ea7535a931b9e1a7217abf550","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-02-27 03:58:18.000000000","message":"Patch Set 3: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":3},{"id":"49ccd28779b078b4ce1723d4d2a876b6f26fa88b","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-02-27 05:23:01.000000000","message":"Patch Set 3: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d46dc7b954a94511b15fcc83d75f1980 : SUCCESS in 5m 53s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1b7052030273410594e1419ce1a62fa9 : SUCCESS in 12m 46s","accounts_in_message":[],"_revision_number":3},{"id":"ebdb5834bbdf4ef8e6e5ca3ae7f55d77d0ffbe4a","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-02-27 05:23:02.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":3},{"id":"ba972fbe7ad44b98a00c1a78ecfe0c6f3dace0b4","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-02-27 05:24:57.000000000","message":"Patch Set 3:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1f6bd203393e4dfcb1af28e4798212e2 : SUCCESS in 1m 16s","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"4df1130e1285da2a55569f727abe5077acd4220d","revisions":{"59dc27358ef34d8aff0e9777cb7cf4eefb60a040":{"kind":"REWORK","_number":1,"created":"2021-01-19 19:40:11.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/09/771509/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/09/771509/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/09/771509/1"}}},"commit":{"parents":[{"commit":"c239cc66615b41a0c09e031b3e268c82678bac12","subject":"Add openstack-python3-wallaby-jobs-arm64 job","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c239cc66615b41a0c09e031b3e268c82678bac12"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-01-19 19:24:37.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-01-19 19:34:12.000000000","tz":0},"subject":"Clarify ``reader`` role implementation in persona admin guide","message":"Clarify ``reader`` role implementation in persona admin guide\n\nThe secure RBAC work propogating throughout the community has led to\nsome interesting discussions about how to implement support for\n``reader``. Specifically, should ``reader`` be used for auditing\ndeployments?\n\nSome compliance targets, verified by third-party auditors, require\naccess to sensitive information (e.g., thinking about license keys in\nglance images or volume type encryption metadata in cinder). The concern\nraised among developers updating their default policies to use\n``reader`` roles is if they should be using that role to protect\nsensitive information, especially if it\u0027s the least-authoritative role\nin the hierarchy between reader, member, and admin.\n\nThis documentation is supposed to assist deployers in understanding the\nvarious personas that developers are implementing by default, but it\ndoesn\u0027t call out the complicated relationship we have with ``reader``\nand auditing.\n\nThe change here proposes that we explicitly say that ``reader``\nshouldn\u0027t be used to protect sensitive information, regardless of the\nscope, because ``reader`` was designed to be the least-authoritative\nrole provided by keystone, by default. Instead, service developers\nworking to implement these personas consistently in other services\nshould keep sensitive information, if applicable to their API or\nresources, at the ``admin`` tier of the hierarchy. This provides better\nprotection of sensitive information by not exposing is implicitly.\n\nWe can consider supporting a formal default role for auditing in the\nfuture, but building it outside the default implied role tree so that\nit\u0027s not implied to anyone with a role assignment. This will come at\nanother time and we can use implied roles to re-use all the work we\u0027ve\ndone across OpenStack to implement support for ``reader``.\n\nFor now, ``reader`` should be viewed from the perspective of the\nleast-authoritative permissions grant-able to a given scope (e.g.,\nsystem, domain, or project). Even if ``reader`` has limited use in\nauditing deployments, it\u0027s still incredibly useful for operators\nbecause they have a role they can grant to users with minimal trust, or\nminimal permissions in the deployment.\n\nThis commit acknowledges the use-case for an elevated auditor role and\nthat it\u0027s something we can implement as a formal role in keystone in the\nfuture.\n\nChange-Id: Iea28faf1b3e63c7ab07e90808d2bc76ee3ee0612\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/59dc27358ef34d8aff0e9777cb7cf4eefb60a040"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/59dc27358ef34d8aff0e9777cb7cf4eefb60a040"}]},"branch":"refs/heads/master"},"c71b3fcfba7cfecc5f0e69dcac2f4355fb892f1b":{"kind":"REWORK","_number":2,"created":"2021-02-05 14:28:01.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/09/771509/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/09/771509/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/09/771509/2"}}},"commit":{"parents":[{"commit":"c239cc66615b41a0c09e031b3e268c82678bac12","subject":"Add openstack-python3-wallaby-jobs-arm64 job","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c239cc66615b41a0c09e031b3e268c82678bac12"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-01-19 19:24:37.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-02-05 14:27:30.000000000","tz":0},"subject":"Clarify ``reader`` role implementation in persona admin guide","message":"Clarify ``reader`` role implementation in persona admin guide\n\nThe secure RBAC work propogating throughout the community has led to\nsome interesting discussions about how to implement support for\n``reader``. Specifically, should ``reader`` be used for auditing\ndeployments?\n\nSome compliance targets, verified by third-party auditors, require\naccess to sensitive information (e.g., thinking about license keys in\nglance images or volume type encryption metadata in cinder). The concern\nraised among developers updating their default policies to use\n``reader`` roles is if they should be using that role to protect\nsensitive information, especially if it\u0027s the least-authoritative role\nin the hierarchy between reader, member, and admin.\n\nThis documentation is supposed to assist deployers in understanding the\nvarious personas that developers are implementing by default, but it\ndoesn\u0027t call out the complicated relationship we have with ``reader``\nand auditing.\n\nThe change here proposes that we explicitly say that ``reader``\nshouldn\u0027t be used to protect sensitive information, regardless of the\nscope, because ``reader`` was designed to be the least-authoritative\nrole provided by keystone, by default. Instead, service developers\nworking to implement these personas consistently in other services\nshould keep sensitive information, if applicable to their API or\nresources, at the ``admin`` tier of the hierarchy. This provides better\nprotection of sensitive information by not exposing is implicitly.\n\nWe can consider supporting a formal default role for auditing in the\nfuture, but building it outside the default implied role tree so that\nit\u0027s not implied to anyone with a role assignment. This will come at\nanother time and we can use implied roles to re-use all the work we\u0027ve\ndone across OpenStack to implement support for ``reader``.\n\nFor now, ``reader`` should be viewed from the perspective of the\nleast-authoritative permissions grant-able to a given scope (e.g.,\nsystem, domain, or project). Even if ``reader`` has limited use in\nauditing deployments, it\u0027s still incredibly useful for operators\nbecause they have a role they can grant to users with minimal trust, or\nminimal permissions in the deployment.\n\nThis commit acknowledges the use-case for an elevated auditor role and\nthat it\u0027s something we can implement as a formal role in keystone in the\nfuture.\n\nChange-Id: Iea28faf1b3e63c7ab07e90808d2bc76ee3ee0612\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c71b3fcfba7cfecc5f0e69dcac2f4355fb892f1b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c71b3fcfba7cfecc5f0e69dcac2f4355fb892f1b"}]},"branch":"refs/heads/master"},"4df1130e1285da2a55569f727abe5077acd4220d":{"kind":"REWORK","_number":3,"created":"2021-02-05 14:32:27.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/09/771509/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/09/771509/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/09/771509/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/09/771509/3"}}},"commit":{"parents":[{"commit":"c239cc66615b41a0c09e031b3e268c82678bac12","subject":"Add openstack-python3-wallaby-jobs-arm64 job","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c239cc66615b41a0c09e031b3e268c82678bac12"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-01-19 19:24:37.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-02-05 14:31:51.000000000","tz":0},"subject":"Clarify ``reader`` role implementation in persona admin guide","message":"Clarify ``reader`` role implementation in persona admin guide\n\nThe secure RBAC work propogating throughout the community has led to\nsome interesting discussions about how to implement support for\n``reader``. Specifically, should ``reader`` be used for auditing\ndeployments?\n\nSome compliance targets, verified by third-party auditors, require\naccess to sensitive information (e.g., thinking about license keys in\nglance images or volume type encryption metadata in cinder). The concern\nraised among developers updating their default policies to use\n``reader`` roles is if they should be using that role to protect\nsensitive information, especially if it\u0027s the least-authoritative role\nin the hierarchy between reader, member, and admin.\n\nThis documentation is supposed to assist deployers in understanding the\nvarious personas that developers are implementing by default, but it\ndoesn\u0027t call out the complicated relationship we have with ``reader``\nand auditing.\n\nThe change here proposes that we explicitly say that ``reader``\nshouldn\u0027t be used to protect sensitive information, regardless of the\nscope, because ``reader`` was designed to be the least-authoritative\nrole provided by keystone, by default. Instead, service developers\nworking to implement these personas consistently in other services\nshould keep sensitive information, if applicable to their API or\nresources, at the ``admin`` tier of the hierarchy. This provides better\nprotection of sensitive information by not exposing is implicitly.\n\nWe can consider supporting a formal default role for auditing in the\nfuture, but building it outside the default implied role tree so that\nit\u0027s not implied to anyone with a role assignment. This will come at\nanother time and we can use implied roles to re-use all the work we\u0027ve\ndone across OpenStack to implement support for ``reader``.\n\nFor now, ``reader`` should be viewed from the perspective of the\nleast-authoritative permissions grant-able to a given scope (e.g.,\nsystem, domain, or project). Even if ``reader`` has limited use in\nauditing deployments, it\u0027s still incredibly useful for operators\nbecause they have a role they can grant to users with minimal trust, or\nminimal permissions in the deployment.\n\nThis commit acknowledges the use-case for an elevated auditor role and\nthat it\u0027s something we can implement as a formal role in keystone in the\nfuture.\n\nChange-Id: Iea28faf1b3e63c7ab07e90808d2bc76ee3ee0612\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/4df1130e1285da2a55569f727abe5077acd4220d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/4df1130e1285da2a55569f727abe5077acd4220d"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"status":"CLOSED","labels":[{"label":"Verified","status":"OK","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"OK","applied_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}},{"label":"Workflow","status":"OK","applied_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}}]}],"submit_requirements":[{"name":"Verified","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Verified\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}},{"name":"Workflow","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Workflow\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}}]}
