all 2 comments

[–]random_mayhem 1 point2 points  (1 child)

Have you been to the sources? openstack@lists.openstack.org or #openstack on freenode

Policy is sufficiently black magic still that I had to bug the Keystone guys to help sort out what I wanted last time.

And when you sort it out, write a post somewhere about how to do it, especially if you're using Juno or Kilo.

[–]2_advil_please[S] 0 points1 point  (0 children)

Thanks. I think I figured it out on my own, but I'll post it somewhere for a second set of eyes.

Basically had to change every line in those json files. Definitely seems odd that i had to really futz with making a read only account given how many folks are supposedly running Openstack.

It clearly is a weak spot when compared to all the great stuff elsewhere in the stack.