[
https://issues.apache.org/jira/browse/HDDS-16112?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Huang Kuan Hao updated HDDS-16112:
----------------------------------
Description:
{\{OzoneContainer}} runs non-secure only, so S3G accepts any access key/secret.
Add a secure variant to exercise real SigV4 validation, ACLs and the S3 secret
flow.
- Add \{{withSecurityEnabled()}} to start Ozone in secure mode
- Run a KDC sidecar (\{{docker.ozone-testkr5b.image}}, as in
\{{compose/ozonesecure}}) on a shared Testcontainers \{{Network}}
- Provision principals/keytabs; fetch real S3 credentials via \{{ozone s3
getsecret}} and return them from \{{getAccessKey()}}/\{{getSecretKey()}}
- Add a smoke test: a signed S3 op succeeds with the fetched secret, wrong
credentials are rejected
Note: no secure all-in-one image exists yet — either build one, or compose the
all-in-one image with a KDC and secure \{{docker-config}}.
was:
{\{OzoneContainer}} runs non-secure only, so S3G accepts any access key/secret.
Add a secure variant to exercise real SigV4 validation, ACLs and the S3 secret
flow.
- Add \{{withSecurityEnabled()}} to start Ozone in secure mode
- Run a KDC sidecar (\{{docker.ozone-testkr5b.image}}, as in
\{{compose/ozonesecure}}) on a shared Testcontainers \{{Network}}
- Provision principals/keytabs; fetch real S3 credentials via \{{ozone s3
getsecret}} and return them from \{{getAccessKey()}}/\{{getSecretKey()}}
- Add a smoke test: a signed S3 op succeeds with the fetched secret, wrong
credentials are rejected
Note: no secure all-in-one image exists yet — either build one, or compose the
all-in-one image with a KDC and secure \{{docker-config}}.
> OzoneContainer: optional secure (Kerberos) mode
> -----------------------------------------------
>
> Key: HDDS-16112
> URL: https://issues.apache.org/jira/browse/HDDS-16112
> Project: Apache Ozone
> Issue Type: Sub-task
> Reporter: Huang Kuan Hao
> Assignee: Huang Kuan Hao
> Priority: Major
>
> {\{OzoneContainer}} runs non-secure only, so S3G accepts any access
> key/secret. Add a secure variant to exercise real SigV4 validation, ACLs and
> the S3 secret flow.
> - Add \{{withSecurityEnabled()}} to start Ozone in secure mode
> - Run a KDC sidecar (\{{docker.ozone-testkr5b.image}}, as in
> \{{compose/ozonesecure}}) on a shared Testcontainers \{{Network}}
> - Provision principals/keytabs; fetch real S3 credentials via \{{ozone s3
> getsecret}} and return them from \{{getAccessKey()}}/\{{getSecretKey()}}
> - Add a smoke test: a signed S3 op succeeds with the fetched secret, wrong
> credentials are rejected
> Note: no secure all-in-one image exists yet — either build one, or compose
> the all-in-one image with a KDC and secure \{{docker-config}}.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]