patrole_tempest_plugin.policy_authority module¶
Bases:
patrole_tempest_plugin.rbac_authority.RbacAuthorityA class that uses
oslo.policyfor validating RBAC.Checks if a given rule in a policy is allowed with given role.
- Parameters
rule_name (string) – Policy name to pass to``oslo.policy``.
roles (List[string]) – List of roles to validate for authorization.
- Raises
RbacParsingException – If
rule_namedoes not exist in the cloud (in policy file or among registered in-code policy defaults).
Dynamically discover the policy file for each service in
cls.available_services. Pick all candidate paths found out of the potential paths in[patrole] custom_policy_files.
Validate whether the service passed to
__init__exists.