This file is indexed.

/etc/designate/policy.json is in designate-common 1:2.0.0-0ubuntu1.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
{
    "admin": "role:admin or is_admin:True",
    "primary_zone": "target.zone_type:SECONDARY",

    "owner": "tenant:%(tenant_id)s",
    "admin_or_owner": "rule:admin or rule:owner",
    "target": "tenant:%(target_tenant_id)s",
    "owner_or_target":"rule:target or rule:owner",
    "admin_or_owner_or_target":"rule:owner_or_target or rule:admin",
    "admin_or_target":"rule:admin or rule:target",

    "zone_primary_or_admin": "('PRIMARY':%(zone_type)s and rule:admin_or_owner) OR ('SECONDARY':%(zone_type)s AND is_admin:True)",

    "default": "rule:admin_or_owner",

    "all_tenants": "rule:admin",

    "edit_managed_records" : "rule:admin",

    "use_low_ttl": "rule:admin",

    "get_quotas": "rule:admin_or_owner",
    "get_quota": "rule:admin_or_owner",
    "set_quota": "rule:admin",
    "reset_quotas": "rule:admin",

    "create_tld": "rule:admin",
    "find_tlds": "rule:admin",
    "get_tld": "rule:admin",
    "update_tld": "rule:admin",
    "delete_tld": "rule:admin",

    "create_tsigkey": "rule:admin",
    "find_tsigkeys": "rule:admin",
    "get_tsigkey": "rule:admin",
    "update_tsigkey": "rule:admin",
    "delete_tsigkey": "rule:admin",

    "find_tenants": "rule:admin",
    "get_tenant": "rule:admin",
    "count_tenants": "rule:admin",

    "create_zone": "rule:admin_or_owner",
    "get_zones": "rule:admin_or_owner",
    "get_zone": "rule:admin_or_owner",
    "get_zone_servers": "rule:admin_or_owner",
    "find_zones": "rule:admin_or_owner",
    "find_zone": "rule:admin_or_owner",
    "update_zone": "rule:admin_or_owner",
    "delete_zone": "rule:admin_or_owner",
    "xfr_zone": "rule:admin_or_owner",
    "abandon_zone": "rule:admin",
    "count_zones": "rule:admin_or_owner",
    "count_zones_pending_notify": "rule:admin_or_owner",
    "purge_zones": "rule:admin",
    "touch_zone": "rule:admin_or_owner",

    "create_recordset": "rule:zone_primary_or_admin",
    "get_recordsets": "rule:admin_or_owner",
    "get_recordset": "rule:admin_or_owner",
    "find_recordsets": "rule:admin_or_owner",
    "find_recordset": "rule:admin_or_owner",
    "update_recordset": "rule:zone_primary_or_admin",
    "delete_recordset": "rule:zone_primary_or_admin",
    "count_recordset": "rule:admin_or_owner",

    "create_record": "rule:admin_or_owner",
    "get_records": "rule:admin_or_owner",
    "get_record": "rule:admin_or_owner",
    "find_records": "rule:admin_or_owner",
    "find_record": "rule:admin_or_owner",
    "update_record": "rule:admin_or_owner",
    "delete_record": "rule:admin_or_owner",
    "count_records": "rule:admin_or_owner",

    "use_sudo": "rule:admin",

    "create_blacklist": "rule:admin",
    "find_blacklist": "rule:admin",
    "find_blacklists": "rule:admin",
    "get_blacklist": "rule:admin",
    "update_blacklist": "rule:admin",
    "delete_blacklist": "rule:admin",
    "use_blacklisted_zone": "rule:admin",

    "create_pool": "rule:admin",
    "find_pools": "rule:admin",
    "find_pool": "rule:admin",
    "get_pool": "rule:admin",
    "update_pool": "rule:admin",
    "delete_pool": "rule:admin",
    "zone_create_forced_pool": "rule:admin",

    "diagnostics_ping": "rule:admin",
    "diagnostics_sync_zones": "rule:admin",
    "diagnostics_sync_zone": "rule:admin",
    "diagnostics_sync_record": "rule:admin",

    "create_zone_transfer_request": "rule:admin_or_owner",
    "get_zone_transfer_request": "rule:admin_or_owner or tenant:%(target_tenant_id)s or None:%(target_tenant_id)s",
    "get_zone_transfer_request_detailed": "rule:admin_or_owner",
    "find_zone_transfer_requests": "@",
    "find_zone_transfer_request": "@",
    "update_zone_transfer_request": "rule:admin_or_owner",
    "delete_zone_transfer_request": "rule:admin_or_owner",

    "create_zone_transfer_accept": "rule:admin_or_owner or tenant:%(target_tenant_id)s or None:%(target_tenant_id)s",
    "get_zone_transfer_accept": "rule:admin_or_owner",
    "find_zone_transfer_accepts": "rule:admin",
    "find_zone_transfer_accept": "rule:admin",
    "update_zone_transfer_accept": "rule:admin",
    "delete_zone_transfer_accept": "rule:admin",

    "create_zone_import": "rule:admin_or_owner",
    "find_zone_imports": "rule:admin_or_owner",
    "get_zone_import": "rule:admin_or_owner",
    "update_zone_import": "rule:admin_or_owner",
    "delete_zone_import": "rule:admin_or_owner",

    "zone_export": "rule:admin_or_owner",
    "create_zone_export": "rule:admin_or_owner",
    "find_zone_exports": "rule:admin_or_owner",
    "get_zone_export": "rule:admin_or_owner",
    "update_zone_export": "rule:admin_or_owner",
    "delete_zone_export": "rule:admin_or_owner"
}