Skip to content

Commit 6bcff46

Browse files
kgubefkr
authored andcommitted
Add reference for RBAC policy change
Signed-off-by: Konrad Gube <[email protected]>
1 parent a005f62 commit 6bcff46

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

Standards/scs-xxxx-v1-provider-network-standard.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -218,6 +218,7 @@ CSPs **MUST** externally route any public IP addresses allocated from subnets of
218218
CSPs **MUST** provide dynamic routing for all project-allocated public IP-prefixes via the standard provider network.
219219

220220
By default, users **SHOULD** be prohibited by policy from creating Networking RBAC rules, to prevent the creation of faux provider networks.
221+
The necessary policy change to implement this restriction for the Neutron API can be found in the Networking RBAC documentation [^rbac].
221222

222223
## Conformance Tests
223224

@@ -231,3 +232,4 @@ By default, users **SHOULD** be prohibited by policy from creating Networking RB
231232
[^pf]: <https://docs.openstack.org/api-ref/network/v2/index.html#floating-ips-port-forwarding>
232233
[^ds]: <https://docs.openstack.org/neutron/2024.1/admin/config-ipv6.html>
233234
[^aa]: <https://docs.openstack.org/neutron/2024.1/admin/config-auto-allocation.html>
235+
[^rbac]: <https://docs.openstack.org/neutron/2024.1/admin/config-rbac.html#preventing-regular-users-from-sharing-objects-with-each-other>

0 commit comments

Comments
 (0)