7.7. Secure metadef APIs
In Red Hat OpenStack Services on OpenShift (RHOSO), you can define key value pairs and tag metadata with metadata definition (metadef) APIs. There is no limit on the number of metadef namespaces, objects, properties, resources, or tags that you can create.
Image service policies control metadef APIs. By default, only administrators can create, update, or delete (CUD) metadef APIs. This limitation prevents metadef APIs from exposing information to unauthorized users and mitigates the risk of a malicious user filling the Image service (glance) database with unlimited resources, which can create a denial of service (DoS) style attack.