Policy Framework in STP
This wiki is used as a starting point to kick off the discuss of Policy support in STP. Johnson Ma
- 1 Introduction
- 2 Use Cases
- 3 Design Map
- 4 Policy Registry
- 5 Policy Creation
- 6 Policy Validation
- 7 Policy Association
- 8 Screenshots
- 9 User Roles
- 10 Runtime support
- 11 Example
- 12 Questions
This doc is aiming to define a framework to enforce SOA policy during component development and deployment
The Policy Registry will hold all policy templates to share cross projects. It will provide interface to lookup/add/remove/update policies in the registry.
In the first version, it will be implemented a xml file for simplicity. Later on, we maybe move on to use embedded database for better performance.
Policy Registry Service
provide interface to lookup/add/remove/update policy in the database
Policy Set Extension Point
Extension point to allow user to add pre-defined policy set to the registry.
The policy validation framework is used to define a validation mechanism when applying ws-policy. Policy is created by policy editor. We will write provide a policy validation rule editor for user to dynamic add/remove validation rules as well.
The validation rules will cover following category:
Define dependencies relationship between policies. Example:
<validation> <rule> <dependency policy_id = "policy A"> <on policy_id="policy B", version="2.0"/> <on policy_id="policy C"/> </dependency> </rule> </validation>
Define conflict relationship between policies Example:
<validation> <rule> <conflict policy_id = "policy A"> <with policy_id="policy D", version="2.0" /> <with policy_id="policy E" /> </conflict> </rule> </validation>
Policy Subject Constraints
Define the subject set with the policy may apply Example:"
<validation> <rule> <subjects policy_id = "policy A"> <subject>endpoint</subject> <subject>message</subject> </subjects> </rule> <rule> <subjects policy_id = "policy B"> <subject>message</subject> </subjects> </rule> </validation>
Policy Validation Engine Implementation
Need to write a engine to support the about validation rules. When user add a policy, we will call the engine to do the validating, the give meaningful error message if any.
Need to looking into the emf.validation to see if we can use use it here. User defines the validation rules from GUI. How to translate those rules to emf validator class on the fly is a problem in that case.
rule based xml validator in stp
Alternative, we may think about extend the current rule based xml validator for policy validation engine here. ?
*Policy Developer -- write policies for projects, company or domain *Service Developer -- write policy, config and apply existing policy to service component. *Deployment Assembler -- apply policies to services during deployment *Operator -- dynamic config/modify policy at runtime.
Relations with SCA Policy Framework?
The SCA policy association framework allows policies and policy subjects specified using WS-Policy and WS-PolicyAttachment, as well as with other policy languages, to be associated with SCA components.