summaryrefslogtreecommitdiffstats
path: root/keystone-moon/examples/moon
diff options
context:
space:
mode:
Diffstat (limited to 'keystone-moon/examples/moon')
-rw-r--r--keystone-moon/examples/moon/policies/policy_authz/assignment.json18
-rw-r--r--keystone-moon/examples/moon/policies/policy_authz/rule.json18
2 files changed, 4 insertions, 32 deletions
diff --git a/keystone-moon/examples/moon/policies/policy_authz/assignment.json b/keystone-moon/examples/moon/policies/policy_authz/assignment.json
index 6482830c..7a6c722e 100644
--- a/keystone-moon/examples/moon/policies/policy_authz/assignment.json
+++ b/keystone-moon/examples/moon/policies/policy_authz/assignment.json
@@ -43,25 +43,13 @@
"object_assignments": {
"object_security_level": {
- "servers": ["low"],
- "vm1": ["low"],
- "vm2": ["medium"],
- "file1": ["low"],
- "file2": ["medium"]
+ "servers": ["low"]
},
"type": {
- "servers": ["computing"],
- "vm1": ["computing"],
- "vm2": ["computing"],
- "file1": ["storage"],
- "file2": ["storage"]
+ "servers": ["computing"]
},
"object_id": {
- "servers": ["servers"],
- "vm1": ["vm1"],
- "vm2": ["vm2"],
- "file1": ["file1"],
- "file2": ["file2"]
+ "servers": ["servers"]
}
}
}
diff --git a/keystone-moon/examples/moon/policies/policy_authz/rule.json b/keystone-moon/examples/moon/policies/policy_authz/rule.json
index 73e791d7..25f9d93a 100644
--- a/keystone-moon/examples/moon/policies/policy_authz/rule.json
+++ b/keystone-moon/examples/moon/policies/policy_authz/rule.json
@@ -19,23 +19,7 @@
],
"rbac_rule":[
["dev", "xx", "read", "servers"],
- ["dev", "xx", "read", "vm1"],
- ["dev", "xx", "read", "vm2"],
- ["dev", "xx", "read", "file1"],
- ["dev", "xx", "read", "file2"],
- ["dev", "xx", "write", "vm1"],
- ["dev", "xx", "write", "vm2"],
- ["dev", "xx", "write", "file1"],
- ["dev", "xx", "write", "file2"],
["admin", "xx", "read", "servers"],
- ["admin", "ft", "read", "servers"],
- ["admin", "ft", "read", "vm1"],
- ["admin", "ft", "read", "vm2"],
- ["admin", "ft", "read", "file1"],
- ["admin", "ft", "read", "file2"],
- ["admin", "ft", "write", "vm1"],
- ["admin", "ft", "write", "vm2"],
- ["admin", "ft", "write", "file1"],
- ["admin", "ft", "write", "file2"]
+ ["admin", "ft", "read", "servers"]
]
}