Member or admin. Do you still only have two roles in your cloud? Implementing Role Based Access Controls sounds so easy, but how do you do it without disrupting your users? Well, we made the jump with almost no impact.
Modifying roles in a production environment is a journey fraught with peril and screams of horror. From starting with the community policies through deploying custom roles, we will guide you through:
- Conceptualizing what authority levels should be required
- Visualizing authorities throughout the environment
- Solving the “everyone’s an admin” problem
- Discovering dependencies between OpenStack services
- Working around Keystone domains vs. ignorance of domains
- Planning compartmentalized deployments
- Modifying Horizon for new roles
- Implementing backwards compatibility
- Deploying new policies
- Cleaning up after yourself
After this talk, you’ll be well prepared to proceed safely with your RBAC implementation.
Attendees will learn the best practices we've uncovered for deploying RBAC, as well as hear about the real world experience from our own production deployment. After this talk, attendees will be well prepared to proceed safely with RBAC implementations.