definition subject {}
definition role {
relation include: role
relation glance_image_create_rel: subject:*
permission glance_image_create = glance_image_create_rel + include->glance_image_create
}
definition resource {
relation parent: resource
relation allow: binding
relation deny: binding
permission glance_image_create = allow_glance_image_create - deny_glance_image_create
permission allow_glance_image_create = allow->glance_image_create + parent->allow_glance_image_create
permission deny_glance_image_create = deny->glance_image_create + parent->deny_glance_image_create
}
definition binding {
relation subject: subject
relation role: role
permission glance_image_create = subject & role->glance_image_create
}
that is template
now we have 540 permisiions