Skip to content

Commit

Permalink
Add rationale for keeping the creator role for service accounts
Browse files Browse the repository at this point in the history
Signed-off-by: Markus Hentsch <[email protected]>
  • Loading branch information
markus-hentsch committed May 16, 2024
1 parent 5b571b3 commit a0b332a
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions Standards/scs-03XX-v1-standard-roles.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,7 @@ This offers users easy access to the Key Manager API and aligns the permission s

The "creator" role will be kept for compatibility reasons concerning service integration.
For example, the block storage service Cinder usually has a technical user in Keystone possessing the "creator" role in the "service" project.
Moving such service accounts to the "member" role could introduce undesired access patterns in other APIs that otherwise don't accept the "creator" role but offer a lot of functionality to the "member" role by default.

### Open questions

Expand Down

0 comments on commit a0b332a

Please sign in to comment.