This file is indexed.

/etc/designate/policy.json is in designate-common 2014.1-18+deb8u1.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
{
    "admin": "role:admin or is_admin:True",
    "owner": "tenant_id:%(tenant_id)s",
    "admin_or_owner": "rule:admin or rule:owner",

    "default": "rule:admin_or_owner",

    "get_quotas": "rule:admin_or_owner",
    "get_quota": "rule:admin_or_owner",
    "set_quota": "rule:admin",
    "reset_quotas": "rule:admin",

    "create_server": "rule:admin",
    "find_servers": "rule:admin",
    "get_server": "rule:admin",
    "update_server": "rule:admin",
    "delete_server": "rule:admin",

    "create_tld": "rule:admin",
    "find_tlds": "rule:admin",
    "get_tld": "rule:admin",
    "update_tld": "rule:admin",
    "delete_tld": "rule:admin",

    "create_tsigkey": "rule:admin",
    "find_tsigkeys": "rule:admin",
    "get_tsigkey": "rule:admin",
    "update_tsigkey": "rule:admin",
    "delete_tsigkey": "rule:admin",

    "find_tenants": "rule:admin",
    "get_tenant": "rule:admin",
    "count_tenants": "rule:admin",

    "create_domain": "rule:admin_or_owner",
    "get_domains": "rule:admin_or_owner",
    "get_domain": "rule:admin_or_owner",
    "get_domain_servers": "rule:admin_or_owner",
    "find_domains": "rule:admin_or_owner",
    "find_domain": "rule:admin_or_owner",
    "update_domain": "rule:admin_or_owner",
    "delete_domain": "rule:admin_or_owner",
    "count_domains": "rule:admin_or_owner",
    "touch_domain": "rule:admin_or_owner",

    "create_record": "rule:admin_or_owner",
    "get_records": "rule:admin_or_owner",
    "get_record": "rule:admin_or_owner",
    "find_records": "rule:admin_or_owner",
    "find_record": "rule:admin_or_owner",
    "update_record": "rule:admin_or_owner",
    "delete_record": "rule:admin_or_owner",
    "count_records": "rule:admin_or_owner",

    "use_sudo": "rule:admin",

    "create_blacklist": "rule:admin",
    "find_blacklist": "rule:admin",
    "find_blacklists": "rule:admin",
    "get_blacklist": "rule:admin",
    "update_blacklist": "rule:admin",
    "delete_blacklist": "rule:admin",
    "use_blacklisted_domain": "rule:admin",

    "diagnostics_ping": "rule:admin",
    "diagnostics_sync_domains": "rule:admin",
    "diagnostics_sync_domain": "rule:admin",
    "diagnostics_sync_record": "rule:admin"
}