The following is an overview of all available policies in Designate. For a sample configuration file, refer to policy.yaml.
admin| Default: | role:admin or is_admin:True |
|---|
(no description provided)
primary_zone| Default: | target.zone_type:SECONDARY |
|---|
(no description provided)
owner| Default: | tenant:%(tenant_id)s |
|---|
(no description provided)
admin_or_owner| Default: | rule:admin or rule:owner |
|---|
(no description provided)
default| Default: | rule:admin_or_owner |
|---|
(no description provided)
target| Default: | tenant:%(target_tenant_id)s |
|---|
(no description provided)
owner_or_target| Default: | rule:target or rule:owner |
|---|
(no description provided)
admin_or_owner_or_target| Default: | rule:owner_or_target or rule:admin |
|---|
(no description provided)
admin_or_target| Default: | rule:admin or rule:target |
|---|
(no description provided)
zone_primary_or_admin| Default: | ('PRIMARY':%(zone_type)s and rule:admin_or_owner) OR ('SECONDARY':%(zone_type)s AND is_admin:True) |
|---|
(no description provided)
create_blacklist| Default: |
|
|---|---|
| Operations: |
|
Create blacklist.
find_blacklist| Default: |
|
|---|---|
| Operations: |
|
Find blacklist.
find_blacklists| Default: |
|
|---|---|
| Operations: |
|
Find blacklists.
get_blacklist| Default: |
|
|---|---|
| Operations: |
|
Get blacklist.
update_blacklist| Default: |
|
|---|---|
| Operations: |
|
Update blacklist.
delete_blacklist| Default: |
|
|---|---|
| Operations: |
|
Delete blacklist.
use_blacklisted_zone| Default: |
|
|---|---|
| Operations: |
|
Allowed bypass the blacklist.
all_tenants| Default: | rule:admin |
|---|
Action on all tenants.
edit_managed_records| Default: | rule:admin |
|---|
Edit managed records.
use_low_ttl| Default: | rule:admin |
|---|
Use low TTL.
use_sudo| Default: | rule:admin |
|---|
Accept sudo from user to tenant.
diagnostics_ping| Default: | rule:admin |
|---|
Diagnose ping.
diagnostics_sync_zones| Default: | rule:admin |
|---|
Diagnose sync zones.
diagnostics_sync_zone| Default: | rule:admin |
|---|
Diagnose sync zone.
diagnostics_sync_record| Default: | rule:admin |
|---|
Diagnose sync record.
create_pool| Default: | rule:admin |
|---|
Create pool.
find_pools| Default: |
|
|---|---|
| Operations: |
|
Find pool.
find_pool| Default: |
|
|---|---|
| Operations: |
|
Find pools.
get_pool| Default: |
|
|---|---|
| Operations: |
|
Get pool.
update_pool| Default: | rule:admin |
|---|
Update pool.
delete_pool| Default: | rule:admin |
|---|
Delete pool.
zone_create_forced_pool| Default: |
|
|---|---|
| Operations: |
|
load and set the pool to the one provided in the Zone attributes.
get_quotas| Default: |
|
|---|---|
| Operations: |
|
View Current Project’s Quotas.
get_quota| Default: | rule:admin_or_owner |
|---|
(no description provided)
set_quota| Default: |
|
|---|---|
| Operations: |
|
Set Quotas.
reset_quotas| Default: |
|
|---|---|
| Operations: |
|
Reset Quotas.
find_records| Default: |
|
|---|---|
| Operations: |
|
Find records.
count_records| Default: | rule:admin_or_owner |
|---|
(no description provided)
create_recordset| Default: |
|
|---|---|
| Operations: |
|
Create Recordset
get_recordsets| Default: | rule:admin_or_owner |
|---|
(no description provided)
get_recordset| Default: |
|
|---|---|
| Operations: |
|
Get recordset
update_recordset| Default: |
|
|---|---|
| Operations: |
|
Update recordset
delete_recordset| Default: |
|
|---|---|
| Operations: |
|
Delete RecordSet
count_recordset| Default: | rule:admin_or_owner |
|---|
Count recordsets
find_service_status| Default: |
|
|---|---|
| Operations: |
|
Find a single Service Status
find_service_statuses| Default: |
|
|---|---|
| Operations: |
|
List service statuses.
update_service_status| Default: | rule:admin |
|---|
(no description provided)
find_tenants| Default: | rule:admin |
|---|
Find all Tenants.
get_tenant| Default: | rule:admin |
|---|
Get all Tenants.
count_tenants| Default: | rule:admin |
|---|
Count tenants
create_tld| Default: |
|
|---|---|
| Operations: |
|
Create Tld
find_tlds| Default: |
|
|---|---|
| Operations: |
|
List Tlds
get_tld| Default: |
|
|---|---|
| Operations: |
|
Show Tld
update_tld| Default: |
|
|---|---|
| Operations: |
|
Update Tld
delete_tld| Default: |
|
|---|---|
| Operations: |
|
Delete Tld
create_tsigkey| Default: |
|
|---|---|
| Operations: |
|
Create Tsigkey
find_tsigkeys| Default: |
|
|---|---|
| Operations: |
|
List Tsigkeys
get_tsigkey| Default: |
|
|---|---|
| Operations: |
|
Show a Tsigkey
update_tsigkey| Default: |
|
|---|---|
| Operations: |
|
Update Tsigkey
delete_tsigkey| Default: |
|
|---|---|
| Operations: |
|
Delete a Tsigkey
create_zone| Default: |
|
|---|---|
| Operations: |
|
Create Zone
get_zones| Default: | rule:admin_or_owner |
|---|
(no description provided)
get_zone| Default: |
|
|---|---|
| Operations: |
|
Get Zone
get_zone_servers| Default: | rule:admin_or_owner |
|---|
(no description provided)
find_zones| Default: |
|
|---|---|
| Operations: |
|
List existing zones
update_zone| Default: |
|
|---|---|
| Operations: |
|
Update Zone
delete_zone| Default: |
|
|---|---|
| Operations: |
|
Delete Zone
xfr_zone| Default: |
|
|---|---|
| Operations: |
|
Manually Trigger an Update of a Secondary Zone
abandon_zone| Default: |
|
|---|---|
| Operations: |
|
Abandon Zone
count_zones| Default: | rule:admin_or_owner |
|---|
(no description provided)
count_zones_pending_notify| Default: | rule:admin_or_owner |
|---|
(no description provided)
purge_zones| Default: | rule:admin |
|---|
(no description provided)
touch_zone| Default: | rule:admin_or_owner |
|---|
(no description provided)
zone_export| Default: |
|
|---|---|
| Operations: |
|
Retrive a Zone Export from the Designate Datastore
create_zone_export| Default: |
|
|---|---|
| Operations: |
|
Create Zone Export
find_zone_exports| Default: |
|
|---|---|
| Operations: |
|
List Zone Exports
get_zone_export| Default: |
|
|---|---|
| Operations: |
|
Get Zone Exports
update_zone_export| Default: |
|
|---|---|
| Operations: |
|
Update Zone Exports
create_zone_import| Default: |
|
|---|---|
| Operations: |
|
Create Zone Import
find_zone_imports| Default: |
|
|---|---|
| Operations: |
|
List all Zone Imports
get_zone_import| Default: |
|
|---|---|
| Operations: |
|
Get Zone Imports
update_zone_import| Default: |
|
|---|---|
| Operations: |
|
Update Zone Imports
delete_zone_import| Default: |
|
|---|---|
| Operations: |
|
Delete a Zone Import
create_zone_transfer_accept| Default: |
|
|---|---|
| Operations: |
|
Create Zone Transfer Accept
get_zone_transfer_accept| Default: |
|
|---|---|
| Operations: |
|
Get Zone Transfer Accept
find_zone_transfer_accepts| Default: |
|
|---|---|
| Operations: |
|
List Zone Transfer Accepts
find_zone_transfer_accept| Default: | rule:admin |
|---|
(no description provided)
update_zone_transfer_accept| Default: |
|
|---|---|
| Operations: |
|
Update a Zone Transfer Accept
delete_zone_transfer_accept| Default: | rule:admin |
|---|
(no description provided)
create_zone_transfer_request| Default: |
|
|---|---|
| Operations: |
|
Create Zone Transfer Accept
get_zone_transfer_request| Default: |
|
|---|---|
| Operations: |
|
Show a Zone Transfer Request
get_zone_transfer_request_detailed| Default: | rule:admin_or_owner |
|---|
(no description provided)
find_zone_transfer_requests| Default: |
|
|---|---|
| Operations: |
|
List Zone Transfer Requests
find_zone_transfer_request| Default: | @ |
|---|
(no description provided)
update_zone_transfer_request| Default: |
|
|---|---|
| Operations: |
|
Update a Zone Transfer Request
delete_zone_transfer_request| Default: |
|
|---|---|
| Operations: |
|
Delete a Zone Transfer Request
Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.