Steve Loughran created HADOOP-15572: ---------------------------------------
Summary: Test S3Guard ops with assumed roles & verify required permissions Key: HADOOP-15572 URL: https://issues.apache.org/jira/browse/HADOOP-15572 Project: Hadoop Common Issue Type: Sub-task Components: fs/s3 Affects Versions: 3.1.0 Reporter: Steve Loughran We haven't documented permissions for S3Guard (WiP of mine); when I try to test using the AssumedRoleCredentialProvider & a role nominally restricted to R/W of S3guard *but not create/delete*, I can still create and destroy buckets Either I've got my list wrong, or how S3Guard sets up its auth isn't right & somehow falling back to the full role -- This message was sent by Atlassian JIRA (v7.6.3#76005) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org