openstack team mailing list archive
-
openstack team
-
Mailing list archive
-
Message #11448
Re: [Metering] External API definition
On Tue, May 8, 2012 at 8:43 PM, Nick Barcet <nick.barcet@xxxxxxxxxxxxx>wrote:
> On 05/08/2012 11:39 AM, Doug Hellmann wrote:
> [..]
> > * Requests must be authenticated (separate from keystone, or only
> linked
> > to accounting type account)
> >
> >
> > What is the motivation for authenticating with a service other than
> > keystone?
>
> The only thing I am trying to express here is that that profiles that
> have access to other OpenStack components should not necessarily have
> access to metering information. This information should be accessible
> only a few select users which group may or may not intersect with users
> stored in Keystone already.
>
I see. Is it enough to say that the API is meant for "admin" users only, or
does that still imply more access than we want to grant?
>
> Nick
>
>
>
Follow ups
References