Uploaded image for project: 'Data Movement as a Platform'
  1. Data Movement as a Platform
  2. DMAAP-1016 [DR] DR provisioning AAF integration
  3. DMAAP-1018

[DR] Create / Request DR AAF permission roles and grant permissions

XMLWordPrintable

    • DMAAP-Dub-07-(02/22-03/21), DMAAP-Dub-08-(03/22-04/04)

      AAF team will need to create the specific roles and permissions. Contact instrumental

      These will have to align with existing DR namespaces in AAF.

      ====================================

      The following are the identified permissions required:

      FEED
      =========

      role create org.onap.dmaap-dr.feed-admin

      perm grant org.onap.dmaap.dr.feed * create org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * edit org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * delete org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * publish org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * suspend org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * restore org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * subscribe org.onap.dmaap-dr.feed-admin
      perm grant org.onap.dmaap.dr.feed * approveSub org.onap.dmaap-dr.feed-admin

      role user add org.onap.dmaap-dr.feed-admin dmaap-dr@dmaap-dr.onap.org

       

      SUB
      ========

      role create org.onap.dmaap-dr.sub-admin

      perm grant org.onap.dmaap.dr.sub * edit org.onap.dmaap-dr.sub-admin
      perm grant org.onap.dmaap.dr.sub * delete org.onap.dmaap-dr.sub-admin
      perm grant org.onap.dmaap.dr.sub * restore org.onap.dmaap-dr.sub-admin
      perm grant org.onap.dmaap.dr.sub * suspend org.onap.dmaap-dr.sub-admin
      perm grant org.onap.dmaap.dr.sub * publish org.onap.dmaap-dr.sub-admin

      role user add org.onap.dmaap-dr.sub-admin dmaap-dr@dmaap-dr.onap.org

       

      AAF defines them in the form : "org.onap.aaf.myapp.myperm|myInstance|myAction"

      Not quite sure what is meant by "myInstance". Guessing this is the AAF target but need to confirm.

      See here for details - AAF docs

      Ans: aaf_instance is not important and only needs to be non null for the aaf cadi to be enforced.

       

       

            Unassigned Unassigned
            efiacor efiacor
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: