)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"2524444f48a55d809f61ec8ae6351585ba091f23","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"f9d1ccc6_74c94329","updated":"2021-12-20 17:26:43.000000000","message":"This patch is fine, but my understanding (from attending the secure rbac meetings) is the feature will be supported in wallaby using policy override files in various projects. Baseline support is provided by [1], and [2]..[5] are examples of patches that refine the policies for specific projects (there are more examples).\n\n[1] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818629\n[2] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818639 (nova)\n[3] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818632 (manila)\n[4] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818634 (cinder)\n[5] https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818640 (neutron)\n\nIs there a similar patch for glance? Again, this patch is fine as is, but I want to be sure there\u0027s no cross-project misunderstanding on how things will work in wallaby.","commit_id":"32f2601c16bd691503f7c3a3fc585842d9767db6"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"ad37bf629867ef51f6958b4c340c1fadcefaefe9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"445a5343_2e81e80e","in_reply_to":"74693cb2_845de65a","updated":"2022-01-04 19:47:29.000000000","message":"This patched merged, but I\u0027m circling back to ack what you wrote and it all makes sense. Thanks!","commit_id":"32f2601c16bd691503f7c3a3fc585842d9767db6"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"9f6282855fead23a9b7d457265b3335d861018b8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"74693cb2_845de65a","in_reply_to":"f9d1ccc6_74c94329","updated":"2021-12-23 05:52:44.000000000","message":"yes right, there are patches which refine the policies for some openstack services but glance policies in Xena implement project-personas by default, so these policies do not need to change. \nHowever, keeping them defined with GlanceApiPolicies will put them in /etc/glance/policy.yaml which will be redundant with the defaults. \nThis may change in the future as glance evolves it\u0027s policies in Yoga to consume system scope.\n\nThere is one patch where just a note added for glance[1]\n\n[1]: https://review.opendev.org/c/openstack/tripleo-heat-templates/+/818637","commit_id":"32f2601c16bd691503f7c3a3fc585842d9767db6"}]}
