diff options
Diffstat (limited to 'src/mon/MonCap.cc')
-rw-r--r-- | src/mon/MonCap.cc | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/src/mon/MonCap.cc b/src/mon/MonCap.cc index bf8eb6fb79d..6f1055091e0 100644 --- a/src/mon/MonCap.cc +++ b/src/mon/MonCap.cc @@ -143,6 +143,8 @@ void MonCapGrant::expand_profile(entity_name_t name) const profile_grants.push_back(MonCapGrant("config-key delete", "key", StringConstraint("", prefix))); } if (profile == "bootstrap-osd") { + profile_grants.push_back(MonCapGrant("mon", MON_CAP_R)); // read monmap + profile_grants.push_back(MonCapGrant("osd", MON_CAP_R)); // read osdmap profile_grants.push_back(MonCapGrant("mon getmap")); profile_grants.push_back(MonCapGrant("osd create")); profile_grants.push_back(MonCapGrant("osd crush set")); // FIXME: constraint this further? @@ -152,6 +154,8 @@ void MonCapGrant::expand_profile(entity_name_t name) const profile_grants.back().command_args["caps_osd"] = StringConstraint("allow *", ""); } if (profile == "bootstrap-mds") { + profile_grants.push_back(MonCapGrant("mon", MON_CAP_R)); // read monmap + profile_grants.push_back(MonCapGrant("osd", MON_CAP_R)); // read osdmap profile_grants.push_back(MonCapGrant("mon getmap")); profile_grants.push_back(MonCapGrant("auth get-or-create")); // FIXME: this can expose other mds keys profile_grants.back().command_args["name"] = StringConstraint("", "mds."); |