    1 ---
    2 features:
    3   - |
    4     Implement secure-rbac for quotas resource.
    5 security:
    6   - |
    7     The current policy only allows users with the key-manager:service-admin
    8     role to list, get, add, update or delete project quotas.  The new
    9     policy allows system readers to list quotas and get quotas for specific
   10     projects and system admins (role:admin and system_scope:all) to add,
   11     update and delete project quotas.