codfw1-dev:
- replace 'observer' roles with 'reader' roles
- replace 'user' roles with 'reader' roles
- replace 'projectadmin' role with 'member' role
- remove old 'user' and 'projectadmin' roles
eqiad1:
- replace 'observer' roles with 'reader' roles
- replace 'user' roles with 'reader' roles
- replace 'projectadmin' role with 'member' role (?)
- rename old 'user' and 'projectadmin' roles (preserves a revert option)
- remove old 'user' and 'projectadmin' roles
all together:
- update keystonehooks to add ssh rights to readers https://gerrit.wikimedia.org/r/c/operations/puppet/+/893545
- enforce_scope = true
- enforce_new_defaults = true
- remove projectadmin-specific policy rules
- remove observer-specific policy rules
- review and remove as many custom policy rules as possible
- replace most or all uses of 'novaadmin' with service roles with global admin