[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ops-mumble-conf_management-02.txt





Andrew Smith wrote:
> 
> Jon,
> 
> > Policies are configuration information and not all policies will be
> > applied by a person to all items filling a certain 'role'
> > using role in
> > the policy context.  In the end some people have privaleges
> > that others
> > do not.  The configuration management system we propose must deal with
> > the fact that network wide configuration information (what people call
> > policies) can not be applied blindly by a device to all instances of
> > contained objects which match a particular set of roles.
> 
> I think this is where we disagree: I think it extremely important that we be
> able to use a policy-role abstraction *without exceptions* that a device has
> to take into consideration. As soon as you push the exception cases down to
> the device we have lost all of the value of the policy-role abstraction. The
> device *has* to be able to blindly apply the information with only the
> policy-role to check against.
> 
> Andrew
>

Then I guess we will have to disagree. I believe there is value, even
though it is necessary to deal with the 'exceptions'  Don't forget that
there will be many policies sent to each device because there are so
many different combinations of roles. This is my view based on what I
have observed in people's nets so far.

/jon