oslo.policy
Oslo Policy library
Decision gist · record as of 2026-08-14
Yes, if you are building or operating an OpenStack cloud or service. oslo.policy is the standard RBAC enforcement library for OpenStack and is actively maintained with no known vulnerabilities. It has low install friction and permissive licensing. Not relevant for non-OpenStack projects.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later.
- Low install friction; pure Python wheel with no compiled dependencies.
- Active maintenance status with a release within the last 37 days.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for proprietary OpenStack deployments.
last release 2026-07-08 (37 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 389,756 downloads/mo, #7,026 on PyPI
Alternatives
Verify before relying
pip install oslo.policy
from oslo_policy import policy
from oslo_policy import opts
opts.register_opts(policy.policy_opts)
policy.init()- Whether the package works standalone or requires a full OpenStack environment to be useful.
- How policy rules are typically authored and where they are stored (file format, location).
- Whether stevedore integration enables plugin-based policy backends or is only for internal extension discovery.
What it is and what it does
oslo.policy is an OpenStack library that provides the core machinery for enforcing role-based access control (RBAC) policies across OpenStack services. It parses policy rules—typically defined in YAML or JSON—and evaluates them at runtime to determine whether a user with a given set of roles and attributes is permitted to perform a specific action. The library integrates with oslo.config for configuration management, oslo.context for request context handling, and stevedore for plugin discovery, making it the standard policy enforcement layer for OpenStack deployments.
The package is designed for operators and developers building or extending OpenStack services. It abstracts the policy decision logic so that each service doesn't have to implement its own RBAC engine, and it provides a consistent way to define and audit access rules across the entire cloud platform.
Use it for
- Enforce role-based access control in OpenStack service APIs to restrict who can perform admin, member, or reader actions.
- Define and manage fine-grained policies for cloud resource operations (compute, storage, networking) in a centralized, auditable way.
- Extend policy rules with custom attributes and conditions to implement organization-specific access control requirements.
- Integrate policy enforcement into middleware or service decorators to gate API endpoints based on user roles and context.
- Migrate or validate policy rule syntax across different OpenStack service versions and deployments.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building or operating an OpenStack cloud or service.
oslo.policy is the standard RBAC enforcement library for OpenStack and is actively maintained with no known vulnerabilities. It has low install friction and permissive licensing. Not relevant for non-OpenStack projects.
Install
oslo-policy on PyPI
Before you install
Low install friction; pure Python wheel with no compiled dependencies. Active maintenance status with a release within the last 37 days. Supports current Python versions (3.11–3.14).
Requires Python 3.11 or later.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for proprietary OpenStack deployments.
Quickstart
pip install oslo.policy
from oslo_policy import policy
from oslo_policy import opts
opts.register_opts(policy.policy_opts)
policy.init()
Verify before relying
- Whether the package works standalone or requires a full OpenStack environment to be useful.
- How policy rules are typically authored and where they are stored (file format, location).
- Whether stevedore integration enables plugin-based policy backends or is only for internal extension discovery.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 8 packagesrequestsoslo.configoslo.contextoslo.i18noslo.serializationPyYAMLstevedoreoslo.utils |
| Maintenance | Actively maintained 37 days since the last release |
| First released | |
| Downloads | 389,756 / month, #7,026 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: OpenStackIntended Audience :: Information TechnologyIntended Audience :: System AdministratorsOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonTyping :: Typed |
Evidence: oslo_policy-6.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “RBAC policy enforcement”
- oslo.policyoslo.policy enforces role-based access control (RBAC) policies across…
- sqlalchemy-adapterBridges PyCasbin access-control policies with SQLAlchemy-supported…
- casbinCasbin enforces access control policies (ACL, RBAC, ABAC) by…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also oslo.concurrency · oslo.limit · oslo.middleware · oslo.rootwrap · oslo.vmware · oslo.privsep · invenio-records-permissions · oslo.messaging · oslo.versionedobjects · oslo.db