diff --git a/pkg/keystone/locale/genpolicy.go b/pkg/keystone/locale/genpolicy.go index 310ac220db..ec3cb09561 100644 --- a/pkg/keystone/locale/genpolicy.go +++ b/pkg/keystone/locale/genpolicy.go @@ -157,6 +157,7 @@ func GenerateAllPolicies() []SPolicyData { } } } + ret = append(ret, predefinedPolicyData...) return ret } diff --git a/pkg/keystone/locale/predefined_policies.go b/pkg/keystone/locale/predefined_policies.go index 4b458c3fa7..9b3a1d7268 100644 --- a/pkg/keystone/locale/predefined_policies.go +++ b/pkg/keystone/locale/predefined_policies.go @@ -122,6 +122,9 @@ var ( "list", "get", }, + "projects": { + "list", + }, }, "meter": { "bill_conditions": { @@ -142,12 +145,27 @@ var ( "list", "get", }, + "nodealerts": { + "list", + }, }, "log": { "actions": { "list", }, }, + "devtool": { + "scriptapplyrecords": { + "list", + "get", + }, + }, + "yunionconf": { + "scopedpolicybindings": { + "list", + "get", + }, + }, }, }, { @@ -610,5 +628,68 @@ var ( }, IsPublic: true, }, + { + Name: "sys_opsadmin", + DescriptionCN: "全局系统管理员", + Description: "System-wide operation manager", + Policies: []string{ + "sys-opsadmin", + }, + IsPublic: true, + }, + { + Name: "sys_secadmin", + DescriptionCN: "全局安全管理员", + Description: "System-wide security manager", + Policies: []string{ + "sys-secadmin", + }, + IsPublic: true, + }, + { + Name: "sys_adtadmin", + DescriptionCN: "全局审计管理员", + Description: "System-wide audit manager", + Policies: []string{ + "sys-adtadmin", + }, + IsPublic: true, + }, + { + Name: "domain_opsadmin", + DescriptionCN: "组织系统管理员", + Description: "Domain-wide operation manager", + Policies: []string{ + "domain-opsadmin", + }, + IsPublic: true, + }, + { + Name: "domain_secadmin", + DescriptionCN: "组织安全管理员", + Description: "Domain-wide security manager", + Policies: []string{ + "domain-secadmin", + }, + IsPublic: true, + }, + { + Name: "domain_adtadmin", + DescriptionCN: "组织审计管理员", + Description: "Domain-wide audit manager", + Policies: []string{ + "domain-adtadmin", + }, + IsPublic: true, + }, + { + Name: "normal_user", + DescriptionCN: "缺省普通用户角色", + Description: "Default normal user role", + Policies: []string{ + "normal-user", + }, + IsPublic: true, + }, } ) diff --git a/pkg/keystone/locale/predefined_yaml.go b/pkg/keystone/locale/predefined_yaml.go new file mode 100644 index 0000000000..0e78a8db0b --- /dev/null +++ b/pkg/keystone/locale/predefined_yaml.go @@ -0,0 +1,209 @@ +// Copyright 2019 Yunion +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package locale + +import ( + "yunion.io/x/jsonutils" + "yunion.io/x/log" + + "yunion.io/x/onecloud/pkg/util/rbacutils" +) + +var opsAdminPolicy = ` +policy: + compute: + '*': + '*': allow + dynamicschedtags: + '*': deny + recyclebins: + '*': deny + schedpolicies: + '*': deny + schedtags: + '*': deny + secgroups: + '*': deny + servers: + '*': allow + perform: + '*': allow + start: deny + stop: deny + change-owner: deny + image: + '*': + '*': allow + log: + actions: + list: deny +` + +var secAdminPolicy = ` +policy: + compute: + '*': + '*': deny + get: allow + list: allow + disks: + '*': deny + delete: allow + get: allow + list: allow + perform: + '*': deny + change-owner: allow + purge: allow + dynamicschedtags: + '*': allow + recyclebins: + '*': allow + get: allow + list: allow + schedpolicies: + '*': allow + schedtags: + '*': allow + secgroups: + '*': allow + servers: + '*': deny + delete: allow + get: allow + list: allow + perform: + '*': deny + change-owner: allow + purge: allow + identity: + '*': + '*': allow + image: + '*': + '*': deny + delete: allow + get: allow + list: allow + perform: + '*': deny + change-owner: allow + purge: allow + log: + actions: + list: deny + yunionconf: + '*': + '*': allow +` + +var adtAdminPolicy = ` +policy: + '*': + '*': + '*': deny + log: + '*': + '*': deny + get: allow + list: allow +` + +var normalUserPolicy = ` +policy: + compute: + '*': + '*': deny + list: allow + get: allow + servers: + '*': allow + create: deny + delete: deny + perform: + clone: deny + snapshot-and-clone: deny + purge: deny + change-ipaddr: deny + change-bandwidth: deny + change-config: deny + change-owner: deny + change-disk-storage: deny + image: + images: + '*': deny + list: allow + get: allow +` + +func toJson(yamlDef string) jsonutils.JSONObject { + yaml, err := jsonutils.ParseYAML(yamlDef) + if err != nil { + log.Errorf("fail to parse %s: %s", yamlDef, err) + } + return yaml +} + +var predefinedPolicyData = []SPolicyData{ + { + Name: "sys-opsadmin", + Scope: rbacutils.ScopeSystem, + Policy: toJson(opsAdminPolicy), + Description: "System-wide operation manager", + DescriptionCN: "全局系统管理员权限", + }, + { + Name: "sys-secadmin", + Scope: rbacutils.ScopeSystem, + Policy: toJson(secAdminPolicy), + Description: "System-wide security manager", + DescriptionCN: "全局安全管理员权限", + }, + { + Name: "sys-adtadmin", + Scope: rbacutils.ScopeSystem, + Policy: toJson(adtAdminPolicy), + Description: "System-wide audit manager", + DescriptionCN: "全局审计管理员权限", + }, + { + Name: "domain-opsadmin", + Scope: rbacutils.ScopeDomain, + Policy: toJson(opsAdminPolicy), + Description: "Domain-wide operation manager", + DescriptionCN: "组织系统管理员权限", + }, + { + Name: "domain-secadmin", + Scope: rbacutils.ScopeDomain, + Policy: toJson(secAdminPolicy), + Description: "Domain-wide security manager", + DescriptionCN: "组织安全管理员权限", + }, + { + Name: "domain-adtadmin", + Scope: rbacutils.ScopeDomain, + Policy: toJson(adtAdminPolicy), + Description: "Domain-wide audit manager", + DescriptionCN: "组织审计管理员权限", + }, + { + Name: "normal-user", + Scope: rbacutils.ScopeProject, + Policy: toJson(normalUserPolicy), + Description: "Default policy for normal user", + DescriptionCN: "普通用户默认权限", + }, +} diff --git a/pkg/mcclient/options/compute/servers.go b/pkg/mcclient/options/compute/servers.go index a5d6580d2f..3de0a17a06 100644 --- a/pkg/mcclient/options/compute/servers.go +++ b/pkg/mcclient/options/compute/servers.go @@ -421,6 +421,8 @@ type ServerCreateOptionalOptions struct { PublicIpChargeType string `help:"newly allocated public ip charge type" choices:"traffic|bandwidth" json:"public_ip_charge_type,omitempty"` GuestImageID string `help:"create from guest image, need to specify the guest image id"` + + EncryptKey string `help:"encryption key"` } func (o *ServerCreateOptions) ToScheduleInput() (*schedapi.ScheduleInput, error) { @@ -508,6 +510,10 @@ func (opts *ServerCreateOptionalOptions) OptionalParams() (*computeapi.ServerCre Secgroups: opts.Secgroups, } + if len(opts.EncryptKey) > 0 { + params.EncryptKeyId = &opts.EncryptKey + } + if regutils.MatchSize(opts.MemSpec) { memSize, err := fileutils.GetSizeMb(opts.MemSpec, 'M', 1024) if err != nil {