Using heat with multiple domains?


We have heat setup and working fine, with a separate "heat" domain to encapsulate the projects/user, and a "Default" domain to contain the actual resources.

The issue is now, we want to have multiple domains next to the "Default", with different rights for different users. I.e., we want a user "devadmin" to have access rights (including heat!) in a new domain "Development".

When we attempt this configuration, the devadmin user is not able to create a new heat stack (regardless of it's rights - it is full admin on the development domain). The error returned is:

"ERROR: You are not authorized to use create."

Is there any additional configuration required on (a) the heat_domain_admin user, or (b) the newly created domain, to allow heat to work in a domain other than "Default" ?