+invirt-remote (0.3.8) unstable; urgency=low
+
+ * Allow anyone on the adminacl to issue web remctls.
+
+ -- Evan Broder <broder@mit.edu> Fri, 27 Feb 2009 21:28:19 -0500
+
invirt-remote (0.3.7) unstable; urgency=low
* Add an availability remctl for when we get around to letting us make
"""
RemConfFS creates a filesytem for configuring remctl, like this:
/
+ |-- adminacl
|-- acl
| |-- machine1
| ...
m.connect('', controller='getroot')
m.connect('acl', controller='getmachines')
m.connect('acl/:machine', controller='getacl')
+ m.connect('adminacl', controller='getadmin')
m.connect('conf', controller='getconf')
return m
def getroot(self, **kw):
- return ['acl', 'conf']
+ return ['adminacl', 'acl', 'conf']
def getacl(self, machine, **kw):
"""Build the ACL file for a machine
def getmachines(self, **kw):
"""Get the list of VMs in the database. Does not cache to prevent race conditions."""
return list(row[0] for row in database.session.execute(sa.sql.select([database.Machine.c.name])))
+
+ def getadmin(self, **kw):
+ """
+ Get the list of administrators for the global ACL.
+ """
+ acl = [self.userToPrinc(row[0]) for row in database.session.execute(sa.sql.select([database.admins_table.c.user]))]
+ acl.append('include /etc/remctl/acl/web\n')
+ return '\n'.join(acl)
def userToPrinc(self, user):
"""Convert Kerberos v4-style names to v5-style and append a default