I have an OpenIO with Keystone (queens) auth cluster.
By default any swift user can configure his own acls and public share url.
1 user = 1 keystone project.
I woulk like to restrict user to only use read/write container/object and do not use acls or public url sharing (on their own containers/objects) -> disable acls and public sharing.
I didn't find any "super admin" acls.
I tried to deny request header with X-Container-Write/Read -> not very effective -> no king of this attributes in headers
ISSUE TYPE
COMPONENT NAME
SDS VERSION
CONFIGURATION
My proxy-server.conf ->
OS / ENVIRONMENT
SUMMARY
I have an OpenIO with Keystone (queens) auth cluster.
By default any swift user can configure his own acls and public share url.
1 user = 1 keystone project.
I woulk like to restrict user to only use read/write container/object and do not use acls or public url sharing (on their own containers/objects) -> disable acls and public sharing.
I didn't find any "super admin" acls.
I tried to deny request header with X-Container-Write/Read -> not very effective -> no king of this attributes in headers
Any idea ?