mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-30 11:45:42 +00:00
* s3/iam: persist IAM-managed OIDC providers in the filer, and trust them after a restart
The S3 server's IAM config loader never read the documented
`oidcProviderStore` key, so the OIDC provider store was always in memory:
a provider created with CreateOpenIDConnectProvider lived in one gateway's
process, was lost on restart, and was never seen by peers. The
/etc/iam/oidc-providers metadata subscription refreshed from that empty
in-memory store.
- Read `oidcProviderStore` and pass it to the IAM manager. With an IAM
config file the default stays memory. With no config file (zero-config
IAM, as `weed filer -s3` and operator-managed clusters run) it defaults
to the filer: there is nothing static to shadow, and providers created at
runtime otherwise vanish on restart.
- With a store that outlives the process, load the STS runtime view from it
at startup, so providers created on an earlier boot or on a peer are
trusted without waiting for the next mutation.
- If the store cannot be read at startup (a filer not up yet), the load is
retried in the background with backoff until it succeeds: the metadata
subscription reports only later changes, so providers already stored would
otherwise stay unknown to STS until one of them changed.
- Mark records mirrored from STS.Providers as `source: static-config`, and
at startup delete such records whose provider has left the config, so
removing a provider from the config file still revokes it. Records created
through the IAM API are never pruned.
- The filer store reported every failed lookup, an unreachable filer
included, as ErrOIDCProviderNotFound, which CreateOIDCProvider reads as
"free to create". Only a confirmed absence is now not-found.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* s3/iam: keep config-file OIDC providers out of a persistent store
Review of the previous commit found that mirroring the IAM config file's
providers into a persistent store, and pruning them when they leave the
file, breaks as soon as S3 servers share a filer:
- a server prunes stored config-file providers its own file does not list,
including ones a peer's file still defines (a zero-config server prunes
them all);
- mirroring overwrites an API-created provider with the same ARN and marks
it config-owned, so a later prune deletes it;
- a failed mirror write or a failed prune leaves a stale record trusted;
- a mirrored record is loaded into STS at startup as an IAM-managed provider
and shadows the config-file provider, dropping the settings a record does
not carry (jwksUri, roleMapping, policyClaim, ...).
A persistent store now never receives the config file's providers. STS keeps
serving them from its static configuration, as it always has; the IAM API
lists and returns them from memory, refuses to change or delete them
(UnmodifiableEntity; change them in the file) and to create another provider
with their ARN (EntityAlreadyExists). The store holds only providers created
through the IAM API, and those are what startup loads into STS. There is
nothing to prune, so the source marker is gone. An in-memory store keeps its
behaviour: the config file's providers are records in it, as before.
buildOIDCProviderFromRecord also carries PolicyClaim and
AllowedPrincipalTagKeys now; they were dropped whenever an API-created
provider was loaded into STS.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* s3/iam: send UnmodifiableEntity as a 400, not an internal error
The IAM API's error writer had no case for UnmodifiableEntity, which the
previous commit returns for a change to a config-file provider, so it went
out as a 500 ServiceFailure that clients retry. AWS sends it as a 400.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* s3/iam: document stored-over-config precedence, drop invented CreateDate, cancel superseded retries
Follow-ups from review of b881982d2:
- A provider stored under the same ARN as a config-file provider takes
precedence in the IAM API, matching STS, which already prefers
IAM-managed providers so that an API call can shadow a bootstrap entry.
Deleting the stored provider brings the config-file one back. This was
already the behaviour; it is now documented and tested.
- A config-file provider no longer reports its server's start time as
CreateDate, which changed on every restart; GetOpenIDConnectProvider now
omits the date for it. An in-memory store still stamps its copies at load,
as before.
- The startup retry runs under a cancellable context, is cancelled when
another store is installed, and retries the store it was started for
rather than reading the manager's field, so replacing the store neither
leaves the old retry running nor races with it (go test -race).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* s3/iam: serialize OIDC provider refreshes so an older snapshot cannot restore a deleted provider
Refreshes run concurrently: after an IAM API change, on a peer's change
and in the startup retry. Each lists the store and then hands STS the
result, so a refresh that listed before a DeleteOIDCProvider could finish
after that call's own refresh and keep the deleted provider trusted until
the next change. Refreshes now hold a lock from the read to the hand-off,
and a startup retry cancelled by installing another store drops its
snapshot instead of applying it.
The retry-cancellation test waits for the retry by polling instead of a
fixed sleep.
* s3/iam: route SetOIDCProviderStore through installOIDCProviderStore
A store installed after Initialize skipped the static-provider overlay
and startup hydration: config-file providers disappeared from the IAM
API, ErrOIDCProviderStatic no longer protected them, and stored
providers were never trusted until the next mutation or peer event.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Chris Lu <chrislusf@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
347 lines
13 KiB
Go
347 lines
13 KiB
Go
package s3api
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"net/url"
|
|
"strings"
|
|
|
|
"github.com/aws/aws-sdk-go/service/iam"
|
|
iamlib "github.com/seaweedfs/seaweedfs/weed/iam"
|
|
"github.com/seaweedfs/seaweedfs/weed/iam/integration"
|
|
)
|
|
|
|
// OIDC provider IAM actions handled by this file.
|
|
const (
|
|
actionGetOpenIDConnectProvider = "GetOpenIDConnectProvider"
|
|
actionListOpenIDConnectProviders = "ListOpenIDConnectProviders"
|
|
actionCreateOpenIDConnectProvider = "CreateOpenIDConnectProvider"
|
|
actionDeleteOpenIDConnectProvider = "DeleteOpenIDConnectProvider"
|
|
actionAddClientIDToOpenIDConnectProvider = "AddClientIDToOpenIDConnectProvider"
|
|
actionRemoveClientIDFromOpenIDConnectProvider = "RemoveClientIDFromOpenIDConnectProvider"
|
|
actionUpdateOpenIDConnectProviderThumbprint = "UpdateOpenIDConnectProviderThumbprint"
|
|
actionTagOpenIDConnectProvider = "TagOpenIDConnectProvider"
|
|
actionUntagOpenIDConnectProvider = "UntagOpenIDConnectProvider"
|
|
)
|
|
|
|
// isOIDCProviderAction reports whether an action belongs to the OIDC provider
|
|
// family. Used by ExecuteAction to short-circuit the S3ApiConfiguration code
|
|
// path for actions that don't operate on it.
|
|
func isOIDCProviderAction(action string) bool {
|
|
switch action {
|
|
case actionGetOpenIDConnectProvider,
|
|
actionListOpenIDConnectProviders,
|
|
actionCreateOpenIDConnectProvider,
|
|
actionDeleteOpenIDConnectProvider,
|
|
actionAddClientIDToOpenIDConnectProvider,
|
|
actionRemoveClientIDFromOpenIDConnectProvider,
|
|
actionUpdateOpenIDConnectProviderThumbprint,
|
|
actionTagOpenIDConnectProvider,
|
|
actionUntagOpenIDConnectProvider:
|
|
return true
|
|
default:
|
|
return false
|
|
}
|
|
}
|
|
|
|
// dispatchOIDCProviderAction handles the OIDC provider IAM actions. Returns a
|
|
// response, the IAM error if any, and a boolean indicating whether the action
|
|
// was recognised (so the caller can fall through when false).
|
|
func (e *EmbeddedIamApi) dispatchOIDCProviderAction(ctx context.Context, values url.Values) (iamlib.RequestIDSetter, *iamError, bool) {
|
|
if !isOIDCProviderAction(values.Get("Action")) {
|
|
return nil, nil, false
|
|
}
|
|
|
|
mgr := e.oidcIAMManager()
|
|
if mgr == nil {
|
|
return nil, &iamError{
|
|
Code: iam.ErrCodeServiceFailureException,
|
|
Error: errors.New("OIDC provider store not configured"),
|
|
}, true
|
|
}
|
|
|
|
switch values.Get("Action") {
|
|
case actionListOpenIDConnectProviders:
|
|
resp, err := e.listOpenIDConnectProviders(ctx, mgr)
|
|
return resp, err, true
|
|
case actionGetOpenIDConnectProvider:
|
|
resp, err := e.getOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionCreateOpenIDConnectProvider:
|
|
resp, err := e.createOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionDeleteOpenIDConnectProvider:
|
|
resp, err := e.deleteOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionAddClientIDToOpenIDConnectProvider:
|
|
resp, err := e.addClientIDToOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionRemoveClientIDFromOpenIDConnectProvider:
|
|
resp, err := e.removeClientIDFromOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionUpdateOpenIDConnectProviderThumbprint:
|
|
resp, err := e.updateOpenIDConnectProviderThumbprint(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionTagOpenIDConnectProvider:
|
|
resp, err := e.tagOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
case actionUntagOpenIDConnectProvider:
|
|
resp, err := e.untagOpenIDConnectProvider(ctx, mgr, values)
|
|
return resp, err, true
|
|
}
|
|
return nil, nil, false
|
|
}
|
|
|
|
// extractMemberList collects all values from `Foo.member.<n>=...` form
|
|
// parameters in order of N. AWS query-string conventions encode list inputs
|
|
// this way, so List/Add/Update/Tag actions all share this helper.
|
|
func extractMemberList(values url.Values, prefix string) []string {
|
|
out := []string{}
|
|
// Members are indexed from 1; iterate until a missing index breaks the run.
|
|
for i := 1; ; i++ {
|
|
key := fmt.Sprintf("%s.member.%d", prefix, i)
|
|
v := values.Get(key)
|
|
if v == "" {
|
|
break
|
|
}
|
|
out = append(out, v)
|
|
}
|
|
return out
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) createOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.CreateOpenIDConnectProviderResponse, *iamError) {
|
|
urlStr := strings.TrimSpace(values.Get("Url"))
|
|
if urlStr == "" {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("Url is required")}
|
|
}
|
|
clientIDs := extractMemberList(values, "ClientIDList")
|
|
if len(clientIDs) == 0 {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("ClientIDList must contain at least one entry")}
|
|
}
|
|
thumbprints := extractMemberList(values, "ThumbprintList")
|
|
tags := extractTags(values)
|
|
|
|
accountID := mgr.GetSTSService().Config.AccountId
|
|
arn, err := integration.DeriveOIDCProviderARN(accountID, urlStr)
|
|
if err != nil {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: err}
|
|
}
|
|
|
|
rec := &integration.OIDCProviderRecord{
|
|
AccountID: accountID,
|
|
ARN: arn,
|
|
URL: urlStr,
|
|
ClientIDs: clientIDs,
|
|
Thumbprints: thumbprints,
|
|
Tags: tags,
|
|
}
|
|
if err := mgr.CreateOIDCProvider(ctx, rec); err != nil {
|
|
if errors.Is(err, integration.ErrOIDCProviderAlreadyExists) {
|
|
return nil, &iamError{Code: iam.ErrCodeEntityAlreadyExistsException, Error: err}
|
|
}
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: err}
|
|
}
|
|
|
|
resp := &iamlib.CreateOpenIDConnectProviderResponse{}
|
|
resp.CreateOpenIDConnectProviderResult.OpenIDConnectProviderArn = rec.ARN
|
|
if len(rec.Tags) > 0 {
|
|
out := make([]*iamlib.IAMTag, 0, len(rec.Tags))
|
|
for k, v := range rec.Tags {
|
|
out = append(out, &iamlib.IAMTag{Key: k, Value: v})
|
|
}
|
|
resp.CreateOpenIDConnectProviderResult.Tags = out
|
|
}
|
|
return resp, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) deleteOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.DeleteOpenIDConnectProviderResponse, *iamError) {
|
|
arn, iamErr := requireProviderArn(values)
|
|
if iamErr != nil {
|
|
return nil, iamErr
|
|
}
|
|
if err := mgr.DeleteOIDCProvider(ctx, arn); err != nil {
|
|
return nil, oidcMutationError(err)
|
|
}
|
|
return &iamlib.DeleteOpenIDConnectProviderResponse{}, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) addClientIDToOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.AddClientIDToOpenIDConnectProviderResponse, *iamError) {
|
|
arn, iamErr := requireProviderArn(values)
|
|
if iamErr != nil {
|
|
return nil, iamErr
|
|
}
|
|
clientID := strings.TrimSpace(values.Get("ClientID"))
|
|
if clientID == "" {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("ClientID is required")}
|
|
}
|
|
if err := mgr.AddClientIDToOIDCProvider(ctx, arn, clientID); err != nil {
|
|
return nil, oidcMutationError(err)
|
|
}
|
|
return &iamlib.AddClientIDToOpenIDConnectProviderResponse{}, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) removeClientIDFromOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.RemoveClientIDFromOpenIDConnectProviderResponse, *iamError) {
|
|
arn, iamErr := requireProviderArn(values)
|
|
if iamErr != nil {
|
|
return nil, iamErr
|
|
}
|
|
clientID := strings.TrimSpace(values.Get("ClientID"))
|
|
if clientID == "" {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("ClientID is required")}
|
|
}
|
|
if err := mgr.RemoveClientIDFromOIDCProvider(ctx, arn, clientID); err != nil {
|
|
return nil, oidcMutationError(err)
|
|
}
|
|
return &iamlib.RemoveClientIDFromOpenIDConnectProviderResponse{}, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) updateOpenIDConnectProviderThumbprint(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.UpdateOpenIDConnectProviderThumbprintResponse, *iamError) {
|
|
arn, iamErr := requireProviderArn(values)
|
|
if iamErr != nil {
|
|
return nil, iamErr
|
|
}
|
|
thumbprints := extractMemberList(values, "ThumbprintList")
|
|
if len(thumbprints) == 0 {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("ThumbprintList must contain at least one entry")}
|
|
}
|
|
if err := mgr.UpdateOIDCProviderThumbprints(ctx, arn, thumbprints); err != nil {
|
|
if errors.Is(err, integration.ErrOIDCProviderStatic) {
|
|
return nil, oidcMutationError(err)
|
|
}
|
|
if errors.Is(err, integration.ErrOIDCProviderNotFound) {
|
|
return nil, &iamError{Code: iam.ErrCodeNoSuchEntityException, Error: err}
|
|
}
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: err}
|
|
}
|
|
return &iamlib.UpdateOpenIDConnectProviderThumbprintResponse{}, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) tagOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.TagOpenIDConnectProviderResponse, *iamError) {
|
|
arn, iamErr := requireProviderArn(values)
|
|
if iamErr != nil {
|
|
return nil, iamErr
|
|
}
|
|
tags := extractTags(values)
|
|
if len(tags) == 0 {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("Tags must contain at least one Key/Value pair")}
|
|
}
|
|
if err := mgr.TagOIDCProvider(ctx, arn, tags); err != nil {
|
|
return nil, oidcMutationError(err)
|
|
}
|
|
return &iamlib.TagOpenIDConnectProviderResponse{}, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) untagOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.UntagOpenIDConnectProviderResponse, *iamError) {
|
|
arn, iamErr := requireProviderArn(values)
|
|
if iamErr != nil {
|
|
return nil, iamErr
|
|
}
|
|
keys := extractMemberList(values, "TagKeys")
|
|
if len(keys) == 0 {
|
|
return nil, &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("TagKeys must contain at least one entry")}
|
|
}
|
|
if err := mgr.UntagOIDCProvider(ctx, arn, keys); err != nil {
|
|
return nil, oidcMutationError(err)
|
|
}
|
|
return &iamlib.UntagOpenIDConnectProviderResponse{}, nil
|
|
}
|
|
|
|
// extractTags walks the AWS IAM "Tags.member.N.Key / Tags.member.N.Value"
|
|
// query-string convention and returns the parsed map. Returns nil (not an
|
|
// empty map) when no tags are present so the caller can distinguish
|
|
// "untouched" from "empty".
|
|
func extractTags(values url.Values) map[string]string {
|
|
var out map[string]string
|
|
for i := 1; ; i++ {
|
|
k := values.Get(fmt.Sprintf("Tags.member.%d.Key", i))
|
|
if k == "" {
|
|
break
|
|
}
|
|
if out == nil {
|
|
out = make(map[string]string)
|
|
}
|
|
out[k] = values.Get(fmt.Sprintf("Tags.member.%d.Value", i))
|
|
}
|
|
return out
|
|
}
|
|
|
|
func requireProviderArn(values url.Values) (string, *iamError) {
|
|
arn := strings.TrimSpace(values.Get("OpenIDConnectProviderArn"))
|
|
if arn == "" {
|
|
return "", &iamError{Code: iam.ErrCodeInvalidInputException, Error: errors.New("OpenIDConnectProviderArn is required")}
|
|
}
|
|
return arn, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) oidcIAMManager() *integration.IAMManager {
|
|
if e.iam == nil || e.iam.iamIntegration == nil {
|
|
return nil
|
|
}
|
|
provider, ok := e.iam.iamIntegration.(IAMManagerProvider)
|
|
if !ok {
|
|
return nil
|
|
}
|
|
return provider.GetIAMManager()
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) listOpenIDConnectProviders(ctx context.Context, mgr *integration.IAMManager) (*iamlib.ListOpenIDConnectProvidersResponse, *iamError) {
|
|
records, err := mgr.ListOIDCProviders(ctx)
|
|
if err != nil {
|
|
return nil, &iamError{Code: iam.ErrCodeServiceFailureException, Error: err}
|
|
}
|
|
resp := &iamlib.ListOpenIDConnectProvidersResponse{}
|
|
resp.ListOpenIDConnectProvidersResult.OpenIDConnectProviderList = make([]*iamlib.OpenIDConnectProviderListEntry, 0, len(records))
|
|
for _, rec := range records {
|
|
resp.ListOpenIDConnectProvidersResult.OpenIDConnectProviderList = append(
|
|
resp.ListOpenIDConnectProvidersResult.OpenIDConnectProviderList,
|
|
&iamlib.OpenIDConnectProviderListEntry{Arn: rec.ARN},
|
|
)
|
|
}
|
|
return resp, nil
|
|
}
|
|
|
|
func (e *EmbeddedIamApi) getOpenIDConnectProvider(ctx context.Context, mgr *integration.IAMManager, values url.Values) (*iamlib.GetOpenIDConnectProviderResponse, *iamError) {
|
|
arn := strings.TrimSpace(values.Get("OpenIDConnectProviderArn"))
|
|
if arn == "" {
|
|
return nil, &iamError{
|
|
Code: iam.ErrCodeInvalidInputException,
|
|
Error: fmt.Errorf("OpenIDConnectProviderArn is required"),
|
|
}
|
|
}
|
|
rec, err := mgr.GetOIDCProvider(ctx, arn)
|
|
if err != nil {
|
|
return nil, &iamError{Code: iam.ErrCodeNoSuchEntityException, Error: err}
|
|
}
|
|
resp := &iamlib.GetOpenIDConnectProviderResponse{}
|
|
resp.GetOpenIDConnectProviderResult.Url = rec.URL
|
|
resp.GetOpenIDConnectProviderResult.ClientIDList = append([]string(nil), rec.ClientIDs...)
|
|
resp.GetOpenIDConnectProviderResult.ThumbprintList = append([]string(nil), rec.Thumbprints...)
|
|
if !rec.CreatedAt.IsZero() {
|
|
// AWS uses ISO-8601; the IAM XML format accepts time.Time-string output.
|
|
resp.GetOpenIDConnectProviderResult.CreateDate = rec.CreatedAt.UTC().Format("2006-01-02T15:04:05Z")
|
|
}
|
|
if len(rec.Tags) > 0 {
|
|
tags := make([]*iamlib.IAMTag, 0, len(rec.Tags))
|
|
for k, v := range rec.Tags {
|
|
tags = append(tags, &iamlib.IAMTag{Key: k, Value: v})
|
|
}
|
|
resp.GetOpenIDConnectProviderResult.Tags = tags
|
|
}
|
|
return resp, nil
|
|
}
|
|
|
|
// oidcMutationError maps an IAMManager error from a provider change to its
|
|
// IAM error code. A provider defined in the IAM config file is changed there,
|
|
// not through the API.
|
|
func oidcMutationError(err error) *iamError {
|
|
switch {
|
|
case errors.Is(err, integration.ErrOIDCProviderStatic):
|
|
return &iamError{Code: iam.ErrCodeUnmodifiableEntityException, Error: err}
|
|
case errors.Is(err, integration.ErrOIDCProviderNotFound):
|
|
return &iamError{Code: iam.ErrCodeNoSuchEntityException, Error: err}
|
|
default:
|
|
return &iamError{Code: iam.ErrCodeServiceFailureException, Error: err}
|
|
}
|
|
}
|