mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: predefined ops/sec/adt manager roles (#13801)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
@@ -157,6 +157,7 @@ func GenerateAllPolicies() []SPolicyData {
|
||||
}
|
||||
}
|
||||
}
|
||||
ret = append(ret, predefinedPolicyData...)
|
||||
return ret
|
||||
}
|
||||
|
||||
|
||||
@@ -122,6 +122,9 @@ var (
|
||||
"list",
|
||||
"get",
|
||||
},
|
||||
"projects": {
|
||||
"list",
|
||||
},
|
||||
},
|
||||
"meter": {
|
||||
"bill_conditions": {
|
||||
@@ -142,12 +145,27 @@ var (
|
||||
"list",
|
||||
"get",
|
||||
},
|
||||
"nodealerts": {
|
||||
"list",
|
||||
},
|
||||
},
|
||||
"log": {
|
||||
"actions": {
|
||||
"list",
|
||||
},
|
||||
},
|
||||
"devtool": {
|
||||
"scriptapplyrecords": {
|
||||
"list",
|
||||
"get",
|
||||
},
|
||||
},
|
||||
"yunionconf": {
|
||||
"scopedpolicybindings": {
|
||||
"list",
|
||||
"get",
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
@@ -610,5 +628,68 @@ var (
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "sys_opsadmin",
|
||||
DescriptionCN: "全局系统管理员",
|
||||
Description: "System-wide operation manager",
|
||||
Policies: []string{
|
||||
"sys-opsadmin",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "sys_secadmin",
|
||||
DescriptionCN: "全局安全管理员",
|
||||
Description: "System-wide security manager",
|
||||
Policies: []string{
|
||||
"sys-secadmin",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "sys_adtadmin",
|
||||
DescriptionCN: "全局审计管理员",
|
||||
Description: "System-wide audit manager",
|
||||
Policies: []string{
|
||||
"sys-adtadmin",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "domain_opsadmin",
|
||||
DescriptionCN: "组织系统管理员",
|
||||
Description: "Domain-wide operation manager",
|
||||
Policies: []string{
|
||||
"domain-opsadmin",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "domain_secadmin",
|
||||
DescriptionCN: "组织安全管理员",
|
||||
Description: "Domain-wide security manager",
|
||||
Policies: []string{
|
||||
"domain-secadmin",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "domain_adtadmin",
|
||||
DescriptionCN: "组织审计管理员",
|
||||
Description: "Domain-wide audit manager",
|
||||
Policies: []string{
|
||||
"domain-adtadmin",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
{
|
||||
Name: "normal_user",
|
||||
DescriptionCN: "缺省普通用户角色",
|
||||
Description: "Default normal user role",
|
||||
Policies: []string{
|
||||
"normal-user",
|
||||
},
|
||||
IsPublic: true,
|
||||
},
|
||||
}
|
||||
)
|
||||
|
||||
@@ -0,0 +1,209 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package locale
|
||||
|
||||
import (
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/util/rbacutils"
|
||||
)
|
||||
|
||||
var opsAdminPolicy = `
|
||||
policy:
|
||||
compute:
|
||||
'*':
|
||||
'*': allow
|
||||
dynamicschedtags:
|
||||
'*': deny
|
||||
recyclebins:
|
||||
'*': deny
|
||||
schedpolicies:
|
||||
'*': deny
|
||||
schedtags:
|
||||
'*': deny
|
||||
secgroups:
|
||||
'*': deny
|
||||
servers:
|
||||
'*': allow
|
||||
perform:
|
||||
'*': allow
|
||||
start: deny
|
||||
stop: deny
|
||||
change-owner: deny
|
||||
image:
|
||||
'*':
|
||||
'*': allow
|
||||
log:
|
||||
actions:
|
||||
list: deny
|
||||
`
|
||||
|
||||
var secAdminPolicy = `
|
||||
policy:
|
||||
compute:
|
||||
'*':
|
||||
'*': deny
|
||||
get: allow
|
||||
list: allow
|
||||
disks:
|
||||
'*': deny
|
||||
delete: allow
|
||||
get: allow
|
||||
list: allow
|
||||
perform:
|
||||
'*': deny
|
||||
change-owner: allow
|
||||
purge: allow
|
||||
dynamicschedtags:
|
||||
'*': allow
|
||||
recyclebins:
|
||||
'*': allow
|
||||
get: allow
|
||||
list: allow
|
||||
schedpolicies:
|
||||
'*': allow
|
||||
schedtags:
|
||||
'*': allow
|
||||
secgroups:
|
||||
'*': allow
|
||||
servers:
|
||||
'*': deny
|
||||
delete: allow
|
||||
get: allow
|
||||
list: allow
|
||||
perform:
|
||||
'*': deny
|
||||
change-owner: allow
|
||||
purge: allow
|
||||
identity:
|
||||
'*':
|
||||
'*': allow
|
||||
image:
|
||||
'*':
|
||||
'*': deny
|
||||
delete: allow
|
||||
get: allow
|
||||
list: allow
|
||||
perform:
|
||||
'*': deny
|
||||
change-owner: allow
|
||||
purge: allow
|
||||
log:
|
||||
actions:
|
||||
list: deny
|
||||
yunionconf:
|
||||
'*':
|
||||
'*': allow
|
||||
`
|
||||
|
||||
var adtAdminPolicy = `
|
||||
policy:
|
||||
'*':
|
||||
'*':
|
||||
'*': deny
|
||||
log:
|
||||
'*':
|
||||
'*': deny
|
||||
get: allow
|
||||
list: allow
|
||||
`
|
||||
|
||||
var normalUserPolicy = `
|
||||
policy:
|
||||
compute:
|
||||
'*':
|
||||
'*': deny
|
||||
list: allow
|
||||
get: allow
|
||||
servers:
|
||||
'*': allow
|
||||
create: deny
|
||||
delete: deny
|
||||
perform:
|
||||
clone: deny
|
||||
snapshot-and-clone: deny
|
||||
purge: deny
|
||||
change-ipaddr: deny
|
||||
change-bandwidth: deny
|
||||
change-config: deny
|
||||
change-owner: deny
|
||||
change-disk-storage: deny
|
||||
image:
|
||||
images:
|
||||
'*': deny
|
||||
list: allow
|
||||
get: allow
|
||||
`
|
||||
|
||||
func toJson(yamlDef string) jsonutils.JSONObject {
|
||||
yaml, err := jsonutils.ParseYAML(yamlDef)
|
||||
if err != nil {
|
||||
log.Errorf("fail to parse %s: %s", yamlDef, err)
|
||||
}
|
||||
return yaml
|
||||
}
|
||||
|
||||
var predefinedPolicyData = []SPolicyData{
|
||||
{
|
||||
Name: "sys-opsadmin",
|
||||
Scope: rbacutils.ScopeSystem,
|
||||
Policy: toJson(opsAdminPolicy),
|
||||
Description: "System-wide operation manager",
|
||||
DescriptionCN: "全局系统管理员权限",
|
||||
},
|
||||
{
|
||||
Name: "sys-secadmin",
|
||||
Scope: rbacutils.ScopeSystem,
|
||||
Policy: toJson(secAdminPolicy),
|
||||
Description: "System-wide security manager",
|
||||
DescriptionCN: "全局安全管理员权限",
|
||||
},
|
||||
{
|
||||
Name: "sys-adtadmin",
|
||||
Scope: rbacutils.ScopeSystem,
|
||||
Policy: toJson(adtAdminPolicy),
|
||||
Description: "System-wide audit manager",
|
||||
DescriptionCN: "全局审计管理员权限",
|
||||
},
|
||||
{
|
||||
Name: "domain-opsadmin",
|
||||
Scope: rbacutils.ScopeDomain,
|
||||
Policy: toJson(opsAdminPolicy),
|
||||
Description: "Domain-wide operation manager",
|
||||
DescriptionCN: "组织系统管理员权限",
|
||||
},
|
||||
{
|
||||
Name: "domain-secadmin",
|
||||
Scope: rbacutils.ScopeDomain,
|
||||
Policy: toJson(secAdminPolicy),
|
||||
Description: "Domain-wide security manager",
|
||||
DescriptionCN: "组织安全管理员权限",
|
||||
},
|
||||
{
|
||||
Name: "domain-adtadmin",
|
||||
Scope: rbacutils.ScopeDomain,
|
||||
Policy: toJson(adtAdminPolicy),
|
||||
Description: "Domain-wide audit manager",
|
||||
DescriptionCN: "组织审计管理员权限",
|
||||
},
|
||||
{
|
||||
Name: "normal-user",
|
||||
Scope: rbacutils.ScopeProject,
|
||||
Policy: toJson(normalUserPolicy),
|
||||
Description: "Default policy for normal user",
|
||||
DescriptionCN: "普通用户默认权限",
|
||||
},
|
||||
}
|
||||
@@ -421,6 +421,8 @@ type ServerCreateOptionalOptions struct {
|
||||
PublicIpChargeType string `help:"newly allocated public ip charge type" choices:"traffic|bandwidth" json:"public_ip_charge_type,omitempty"`
|
||||
|
||||
GuestImageID string `help:"create from guest image, need to specify the guest image id"`
|
||||
|
||||
EncryptKey string `help:"encryption key"`
|
||||
}
|
||||
|
||||
func (o *ServerCreateOptions) ToScheduleInput() (*schedapi.ScheduleInput, error) {
|
||||
@@ -508,6 +510,10 @@ func (opts *ServerCreateOptionalOptions) OptionalParams() (*computeapi.ServerCre
|
||||
Secgroups: opts.Secgroups,
|
||||
}
|
||||
|
||||
if len(opts.EncryptKey) > 0 {
|
||||
params.EncryptKeyId = &opts.EncryptKey
|
||||
}
|
||||
|
||||
if regutils.MatchSize(opts.MemSpec) {
|
||||
memSize, err := fileutils.GetSizeMb(opts.MemSpec, 'M', 1024)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user