fix: predefined ops/sec/adt manager roles (#13801)

Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
Jian Qiu
2022-03-27 22:49:22 +08:00
committed by GitHub
co-authored by Qiu Jian
parent 79affb7c81
commit 2553a85a03
4 changed files with 297 additions and 0 deletions
+1
View File
@@ -157,6 +157,7 @@ func GenerateAllPolicies() []SPolicyData {
}
}
}
ret = append(ret, predefinedPolicyData...)
return ret
}
@@ -122,6 +122,9 @@ var (
"list",
"get",
},
"projects": {
"list",
},
},
"meter": {
"bill_conditions": {
@@ -142,12 +145,27 @@ var (
"list",
"get",
},
"nodealerts": {
"list",
},
},
"log": {
"actions": {
"list",
},
},
"devtool": {
"scriptapplyrecords": {
"list",
"get",
},
},
"yunionconf": {
"scopedpolicybindings": {
"list",
"get",
},
},
},
},
{
@@ -610,5 +628,68 @@ var (
},
IsPublic: true,
},
{
Name: "sys_opsadmin",
DescriptionCN: "全局系统管理员",
Description: "System-wide operation manager",
Policies: []string{
"sys-opsadmin",
},
IsPublic: true,
},
{
Name: "sys_secadmin",
DescriptionCN: "全局安全管理员",
Description: "System-wide security manager",
Policies: []string{
"sys-secadmin",
},
IsPublic: true,
},
{
Name: "sys_adtadmin",
DescriptionCN: "全局审计管理员",
Description: "System-wide audit manager",
Policies: []string{
"sys-adtadmin",
},
IsPublic: true,
},
{
Name: "domain_opsadmin",
DescriptionCN: "组织系统管理员",
Description: "Domain-wide operation manager",
Policies: []string{
"domain-opsadmin",
},
IsPublic: true,
},
{
Name: "domain_secadmin",
DescriptionCN: "组织安全管理员",
Description: "Domain-wide security manager",
Policies: []string{
"domain-secadmin",
},
IsPublic: true,
},
{
Name: "domain_adtadmin",
DescriptionCN: "组织审计管理员",
Description: "Domain-wide audit manager",
Policies: []string{
"domain-adtadmin",
},
IsPublic: true,
},
{
Name: "normal_user",
DescriptionCN: "缺省普通用户角色",
Description: "Default normal user role",
Policies: []string{
"normal-user",
},
IsPublic: true,
},
}
)
+209
View File
@@ -0,0 +1,209 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package locale
import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
var opsAdminPolicy = `
policy:
compute:
'*':
'*': allow
dynamicschedtags:
'*': deny
recyclebins:
'*': deny
schedpolicies:
'*': deny
schedtags:
'*': deny
secgroups:
'*': deny
servers:
'*': allow
perform:
'*': allow
start: deny
stop: deny
change-owner: deny
image:
'*':
'*': allow
log:
actions:
list: deny
`
var secAdminPolicy = `
policy:
compute:
'*':
'*': deny
get: allow
list: allow
disks:
'*': deny
delete: allow
get: allow
list: allow
perform:
'*': deny
change-owner: allow
purge: allow
dynamicschedtags:
'*': allow
recyclebins:
'*': allow
get: allow
list: allow
schedpolicies:
'*': allow
schedtags:
'*': allow
secgroups:
'*': allow
servers:
'*': deny
delete: allow
get: allow
list: allow
perform:
'*': deny
change-owner: allow
purge: allow
identity:
'*':
'*': allow
image:
'*':
'*': deny
delete: allow
get: allow
list: allow
perform:
'*': deny
change-owner: allow
purge: allow
log:
actions:
list: deny
yunionconf:
'*':
'*': allow
`
var adtAdminPolicy = `
policy:
'*':
'*':
'*': deny
log:
'*':
'*': deny
get: allow
list: allow
`
var normalUserPolicy = `
policy:
compute:
'*':
'*': deny
list: allow
get: allow
servers:
'*': allow
create: deny
delete: deny
perform:
clone: deny
snapshot-and-clone: deny
purge: deny
change-ipaddr: deny
change-bandwidth: deny
change-config: deny
change-owner: deny
change-disk-storage: deny
image:
images:
'*': deny
list: allow
get: allow
`
func toJson(yamlDef string) jsonutils.JSONObject {
yaml, err := jsonutils.ParseYAML(yamlDef)
if err != nil {
log.Errorf("fail to parse %s: %s", yamlDef, err)
}
return yaml
}
var predefinedPolicyData = []SPolicyData{
{
Name: "sys-opsadmin",
Scope: rbacutils.ScopeSystem,
Policy: toJson(opsAdminPolicy),
Description: "System-wide operation manager",
DescriptionCN: "全局系统管理员权限",
},
{
Name: "sys-secadmin",
Scope: rbacutils.ScopeSystem,
Policy: toJson(secAdminPolicy),
Description: "System-wide security manager",
DescriptionCN: "全局安全管理员权限",
},
{
Name: "sys-adtadmin",
Scope: rbacutils.ScopeSystem,
Policy: toJson(adtAdminPolicy),
Description: "System-wide audit manager",
DescriptionCN: "全局审计管理员权限",
},
{
Name: "domain-opsadmin",
Scope: rbacutils.ScopeDomain,
Policy: toJson(opsAdminPolicy),
Description: "Domain-wide operation manager",
DescriptionCN: "组织系统管理员权限",
},
{
Name: "domain-secadmin",
Scope: rbacutils.ScopeDomain,
Policy: toJson(secAdminPolicy),
Description: "Domain-wide security manager",
DescriptionCN: "组织安全管理员权限",
},
{
Name: "domain-adtadmin",
Scope: rbacutils.ScopeDomain,
Policy: toJson(adtAdminPolicy),
Description: "Domain-wide audit manager",
DescriptionCN: "组织审计管理员权限",
},
{
Name: "normal-user",
Scope: rbacutils.ScopeProject,
Policy: toJson(normalUserPolicy),
Description: "Default policy for normal user",
DescriptionCN: "普通用户默认权限",
},
}
+6
View File
@@ -421,6 +421,8 @@ type ServerCreateOptionalOptions struct {
PublicIpChargeType string `help:"newly allocated public ip charge type" choices:"traffic|bandwidth" json:"public_ip_charge_type,omitempty"`
GuestImageID string `help:"create from guest image, need to specify the guest image id"`
EncryptKey string `help:"encryption key"`
}
func (o *ServerCreateOptions) ToScheduleInput() (*schedapi.ScheduleInput, error) {
@@ -508,6 +510,10 @@ func (opts *ServerCreateOptionalOptions) OptionalParams() (*computeapi.ServerCre
Secgroups: opts.Secgroups,
}
if len(opts.EncryptKey) > 0 {
params.EncryptKeyId = &opts.EncryptKey
}
if regutils.MatchSize(opts.MemSpec) {
memSize, err := fileutils.GetSizeMb(opts.MemSpec, 'M', 1024)
if err != nil {