Skip to content

Commit

Permalink
mgr/dashboard: access_control: add grafana scope read access to *-man…
Browse files Browse the repository at this point in the history
…ager roles

Fixes: https://tracker.ceph.com/issues/41572

Signed-off-by: Ricardo Dias <[email protected]>
  • Loading branch information
rjfd committed Aug 29, 2019
1 parent 7d490c0 commit ea42365
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions src/pybind/mgr/dashboard/services/access_control.py
Original file line number Diff line number Diff line change
Expand Up @@ -112,13 +112,15 @@ def from_dict(cls, r_dict):
Scope.POOL: [_P.READ],
Scope.ISCSI: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.RBD_MIRRORING: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.GRAFANA: [_P.READ],
})


# RadosGW manager role provides all permissions for block related scopes
RGW_MGR_ROLE = Role('rgw-manager', 'RGW Manager', {
Scope.RGW: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.CONFIG_OPT: [_P.READ],
Scope.GRAFANA: [_P.READ],
})


Expand All @@ -131,26 +133,30 @@ def from_dict(cls, r_dict):
Scope.MANAGER: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.CONFIG_OPT: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.LOG: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.GRAFANA: [_P.READ],
})


# Pool manager role provides all permissions for pool related scopes
POOL_MGR_ROLE = Role('pool-manager', 'Pool Manager', {
Scope.POOL: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.CONFIG_OPT: [_P.READ],
Scope.GRAFANA: [_P.READ],
})

# Pool manager role provides all permissions for CephFS related scopes
CEPHFS_MGR_ROLE = Role('cephfs-manager', 'CephFS Manager', {
Scope.CEPHFS: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.CONFIG_OPT: [_P.READ],
Scope.GRAFANA: [_P.READ],
})

GANESHA_MGR_ROLE = Role('ganesha-manager', 'NFS Ganesha Manager', {
Scope.NFS_GANESHA: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.CEPHFS: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.RGW: [_P.READ, _P.CREATE, _P.UPDATE, _P.DELETE],
Scope.CONFIG_OPT: [_P.READ],
Scope.GRAFANA: [_P.READ],
})


Expand Down

0 comments on commit ea42365

Please sign in to comment.