mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
feature: recode cloudcommon policy default/resource codes
This commit is contained in:
@@ -1 +1,15 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package proxy // import "yunion.io/x/onecloud/pkg/cloudcommon/db/proxy"
|
||||
|
||||
@@ -1,3 +1,17 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package proxy
|
||||
|
||||
import (
|
||||
|
||||
@@ -15,7 +15,6 @@
|
||||
package policy
|
||||
|
||||
import (
|
||||
identityapi "yunion.io/x/onecloud/pkg/apis/identity"
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
@@ -30,144 +29,6 @@ var (
|
||||
Action: PolicyActionPerform,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "hosts",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "zones",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "zones",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "metadatas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "storages",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "storages",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "vpcs",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "vpcs",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "wires",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "wires",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "cloudregions",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "cloudregions",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "cachedimages",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "cachedimages",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "dbinstance_skus",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "dbinstance_skus",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "serverskus",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "serverskus",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "secgrouprules",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "elasticcacheskus",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "elasticcacheskus",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "secgrouprules",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "loadbalancerclusters",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "yunionagent",
|
||||
Resource: "notices",
|
||||
@@ -186,132 +47,6 @@ var (
|
||||
Action: PolicyActionCreate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "services",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "services",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Auth: true,
|
||||
Scope: rbacutils.ScopeUser,
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "keypairs",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "keypairs",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "keypairs",
|
||||
Action: PolicyActionCreate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "keypairs",
|
||||
Action: PolicyActionUpdate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "keypairs",
|
||||
Action: PolicyActionDelete,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "identity",
|
||||
Resource: "credentials",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "identity",
|
||||
Resource: "credentials",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "identity",
|
||||
Resource: "credentials",
|
||||
Action: PolicyActionCreate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "identity",
|
||||
Resource: "credentials",
|
||||
Action: PolicyActionUpdate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "identity",
|
||||
Resource: "credentials",
|
||||
Action: PolicyActionDelete,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "yunionconf",
|
||||
Resource: "parameters",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "yunionconf",
|
||||
Resource: "parameters",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "yunionconf",
|
||||
Resource: "parameters",
|
||||
Action: PolicyActionCreate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "yunionconf",
|
||||
Resource: "parameters",
|
||||
Action: PolicyActionUpdate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "notify",
|
||||
Resource: "contacts",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "notify",
|
||||
Resource: "contacts",
|
||||
Action: PolicyActionCreate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "notify",
|
||||
Resource: "contacts",
|
||||
Action: PolicyActionUpdate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "notify",
|
||||
Resource: "contacts",
|
||||
Action: PolicyActionDelete,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -323,78 +58,6 @@ var (
|
||||
Action: PolicyActionPerform,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "region_quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "region_quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "zone_quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "zone_quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "project_quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "project_quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "domain_quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "domain_quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "image_quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "image_quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
// usages for any services
|
||||
// Service: "compute",
|
||||
@@ -402,78 +65,6 @@ var (
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "networks",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "networks",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "images",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "images",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "guestimages",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "guestimages",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "log",
|
||||
Resource: "actions",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "log",
|
||||
Resource: "actions",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "cloudproviders",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: "compute",
|
||||
Resource: "cloudproviders",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "users",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "groups",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -495,39 +86,11 @@ var (
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
// for anonymous update torrent status
|
||||
Auth: false,
|
||||
Scope: rbacutils.ScopeSystem,
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
Service: "image",
|
||||
Resource: "images",
|
||||
Action: PolicyActionPerform,
|
||||
Extra: []string{"update-torrent-status"},
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
// for domain
|
||||
Auth: true,
|
||||
Scope: rbacutils.ScopeDomain,
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
// quotas for any services
|
||||
// Service: "compute",
|
||||
Resource: "quotas",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
// quotas for any services
|
||||
// Service: "compute",
|
||||
Resource: "quotas",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
// usages for any services
|
||||
// Service: "compute",
|
||||
@@ -535,46 +98,6 @@ var (
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "domains",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
// for policies administration
|
||||
Auth: true,
|
||||
Scope: rbacutils.ScopeSystem,
|
||||
DomainId: identityapi.DEFAULT_DOMAIN_ID,
|
||||
Projects: []string{identityapi.SystemAdminProject},
|
||||
Roles: []string{identityapi.SystemAdminRole},
|
||||
Rules: []rbacutils.SRbacRule{
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "policies",
|
||||
Action: PolicyActionCreate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "policies",
|
||||
Action: PolicyActionUpdate,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "policies",
|
||||
Action: PolicyActionList,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
{
|
||||
Service: identityapi.SERVICE_TYPE,
|
||||
Resource: "policies",
|
||||
Action: PolicyActionGet,
|
||||
Result: rbacutils.Allow,
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -14,52 +14,11 @@
|
||||
|
||||
package policy
|
||||
|
||||
import "yunion.io/x/pkg/utils"
|
||||
import (
|
||||
"yunion.io/x/pkg/utils"
|
||||
)
|
||||
|
||||
var (
|
||||
computeSystemResources = []string{
|
||||
"zones",
|
||||
"cloudregions",
|
||||
"serverskus",
|
||||
"cachedimages",
|
||||
"dynamicschedtags",
|
||||
"baremetalagents",
|
||||
"schedpolicies",
|
||||
"dnsrecords",
|
||||
"metadatas",
|
||||
"loadbalancerclusters",
|
||||
"loadbalanceragents",
|
||||
"isolated-devices",
|
||||
"reservedips",
|
||||
}
|
||||
computeDomainResources = []string{
|
||||
"cloudaccounts",
|
||||
"cloudproviders",
|
||||
"recyclebins",
|
||||
// migrate system resources to domain resources
|
||||
"hosts",
|
||||
"vpcs",
|
||||
"storages",
|
||||
"wires",
|
||||
"globalvpcs",
|
||||
"route_tables",
|
||||
"networkinterfaces",
|
||||
"natgateways",
|
||||
"natsentries",
|
||||
"natdentries",
|
||||
}
|
||||
computeUserResources = []string{
|
||||
"keypairs",
|
||||
}
|
||||
|
||||
notifySystemResources = []string{
|
||||
"configs",
|
||||
}
|
||||
notifyDomainResources = []string{}
|
||||
notifyUserResources = []string{
|
||||
"contacts",
|
||||
}
|
||||
|
||||
meterSystemResources = []string{
|
||||
"rates",
|
||||
"res_results",
|
||||
@@ -79,75 +38,30 @@ var (
|
||||
yunionagentDomainResources = []string{}
|
||||
yunionagentUserResources = []string{}
|
||||
|
||||
yunionconfSystemResources = []string{}
|
||||
yunionconfDomainResources = []string{}
|
||||
yunionconfUserResources = []string{
|
||||
"parameters",
|
||||
}
|
||||
|
||||
logSystemResources = []string{}
|
||||
logDomainResources = []string{}
|
||||
logUserResources = []string{}
|
||||
|
||||
identitySystemResources = []string{
|
||||
"identity_providers",
|
||||
"domains",
|
||||
"services",
|
||||
"endpoints",
|
||||
}
|
||||
identityDomainResources = []string{
|
||||
"users",
|
||||
"groups",
|
||||
"projects",
|
||||
"roles",
|
||||
"policies",
|
||||
}
|
||||
identityUserResources = []string{}
|
||||
|
||||
itsmSystemResources = []string{
|
||||
"process-definitions",
|
||||
}
|
||||
itsmDomainResources = []string{}
|
||||
itsmUserResources = []string{}
|
||||
|
||||
cloudeventSystemResoruces = []string{
|
||||
"cloudevents",
|
||||
}
|
||||
|
||||
systemResources = map[string][]string{
|
||||
"compute": computeSystemResources,
|
||||
"notify": notifySystemResources,
|
||||
"meter": meterSystemResources,
|
||||
"k8s": k8sSystemResources,
|
||||
"yunionagent": yunionagentSystemResources,
|
||||
"yunionconf": yunionconfSystemResources,
|
||||
"log": logSystemResources,
|
||||
"identity": identitySystemResources,
|
||||
"itsm": itsmSystemResources,
|
||||
"cloudevent": cloudeventSystemResoruces,
|
||||
}
|
||||
|
||||
domainResources = map[string][]string{
|
||||
"compute": computeDomainResources,
|
||||
"notify": notifyDomainResources,
|
||||
"meter": meterDomainResources,
|
||||
"k8s": k8sDomainResources,
|
||||
"yunionagent": yunionagentDomainResources,
|
||||
"yunionconf": yunionconfDomainResources,
|
||||
"log": logDomainResources,
|
||||
"identity": identityDomainResources,
|
||||
"itsm": itsmDomainResources,
|
||||
}
|
||||
|
||||
userResources = map[string][]string{
|
||||
"compute": computeUserResources,
|
||||
"notify": notifyUserResources,
|
||||
"meter": meterUserResources,
|
||||
"k8s": k8sUserResources,
|
||||
"yunionagent": yunionagentUserResources,
|
||||
"yunionconf": yunionconfUserResources,
|
||||
"log": logUserResources,
|
||||
"identity": identityUserResources,
|
||||
"itsm": itsmUserResources,
|
||||
}
|
||||
)
|
||||
@@ -206,3 +120,15 @@ func isProjectResource(service string, resource string) bool {
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
func RegisterSystemResources(service string, resources []string) {
|
||||
systemResources[service] = resources
|
||||
}
|
||||
|
||||
func RegisterDomainResources(service string, resources []string) {
|
||||
domainResources[service] = resources
|
||||
}
|
||||
|
||||
func RegisterUserResources(service string, resources []string) {
|
||||
userResources[service] = resources
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user