[ 
https://issues.apache.org/jira/browse/MESOS-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Adam B updated MESOS-4843:
--------------------------
    Labels: authorization mesosphere security  (was: mesosphere security)

> Authorize Master Operator Endpoints
> -----------------------------------
>
>                 Key: MESOS-4843
>                 URL: https://issues.apache.org/jira/browse/MESOS-4843
>             Project: Mesos
>          Issue Type: Epic
>          Components: master, security
>            Reporter: Adam B
>            Assignee: Joerg Schad
>              Labels: authorization, mesosphere, security
>
> In a secure, multi-tenant cluster, the operator doesn't want to give every 
> user access to read or modify cluster state/config, nor to perform 
> administrative actions. As such, we need to make sure that all such endpoints 
> are authenticated and authorized.
> We've already added authorization to some operator endpoints (/teardown, 
> /reserve, etc.), but many remain unsecured.
> - /roles, /observe, /registrar, /state-summary
> - /maintenance, /machine,
> - /logging, /profiler, /metrics, /flags, /system/stats.json
> - Leave open? /redirect, /health, /version
> See http://mesos.apache.org/documentation/latest/endpoints/ for a more 
> complete list. Some endpoints (e.g. state.json) will need a finer-grained 
> authz.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to