mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-08-19 21:56:54 +00:00
This commit addresses the user feedback that configuration files should not
need to specify default paths when constants are available.
### Changes Made:
#### Configuration Simplification:
- Removed redundant basePath configurations from iam_config_distributed.json
- All stores now use constants for defaults:
* Sessions: /etc/iam/sessions (DefaultSessionBasePath)
* Policies: /etc/iam/policies (DefaultPolicyBasePath)
* Roles: /etc/iam/roles (DefaultRoleBasePath)
- Eliminated empty storeConfig objects entirely for cleaner JSON
#### Updated Store Implementations:
- FilerPolicyStore: Updated hardcoded path to use /etc/iam/policies
- FilerRoleStore: Updated hardcoded path to use /etc/iam/roles
- All stores consistently align with /etc/ filer convention
#### Runtime Filer Address Integration:
- Updated IAM manager methods to accept filerAddress parameter:
* AssumeRoleWithWebIdentity(ctx, filerAddress, request)
* AssumeRoleWithCredentials(ctx, filerAddress, request)
* IsActionAllowed(ctx, filerAddress, request)
* ExpireSessionForTesting(ctx, filerAddress, sessionToken)
- Enhanced S3IAMIntegration to store filerAddress from S3ApiServer
- Updated all test files to pass test filerAddress ('localhost:8888')
### Benefits:
- ✅ Cleaner, minimal configuration files
- ✅ Consistent use of well-defined constants for defaults
- ✅ No configuration needed for standard use cases
- ✅ Runtime filer address flexibility maintained
- ✅ Aligns with SeaweedFS /etc/ convention throughout
### Breaking Change:
- S3IAMIntegration constructor now requires filerAddress parameter
- All IAM manager methods now require filerAddress as second parameter
- Tests and middleware updated accordingly
178 lines
4.4 KiB
JSON
178 lines
4.4 KiB
JSON
{
|
|
"sts": {
|
|
"tokenDuration": 3600000000000,
|
|
"maxSessionLength": 43200000000000,
|
|
"issuer": "seaweedfs-sts",
|
|
"signingKey": "dGVzdC1zaWduaW5nLWtleS0zMi1jaGFyYWN0ZXJzLWxvbmc=",
|
|
"sessionStoreType": "filer",
|
|
"providers": [
|
|
{
|
|
"name": "keycloak-oidc",
|
|
"type": "oidc",
|
|
"enabled": true,
|
|
"config": {
|
|
"issuer": "http://keycloak:8080/realms/seaweedfs-test",
|
|
"clientId": "seaweedfs-s3",
|
|
"clientSecret": "seaweedfs-s3-secret",
|
|
"jwksUri": "http://keycloak:8080/realms/seaweedfs-test/protocol/openid-connect/certs",
|
|
"scopes": ["openid", "profile", "email", "roles"],
|
|
"claimsMapping": {
|
|
"usernameClaim": "preferred_username",
|
|
"groupsClaim": "roles"
|
|
}
|
|
}
|
|
},
|
|
{
|
|
"name": "mock-provider",
|
|
"type": "mock",
|
|
"enabled": false,
|
|
"config": {
|
|
"issuer": "http://localhost:9999",
|
|
"jwksEndpoint": "http://localhost:9999/jwks"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"policy": {
|
|
"defaultEffect": "Deny",
|
|
"storeType": "filer"
|
|
},
|
|
"roleStore": {
|
|
"storeType": "filer"
|
|
},
|
|
|
|
"roles": [
|
|
{
|
|
"roleName": "S3AdminRole",
|
|
"roleArn": "arn:seaweed:iam::role/S3AdminRole",
|
|
"trustPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": {
|
|
"Federated": "keycloak-oidc"
|
|
},
|
|
"Action": ["sts:AssumeRoleWithWebIdentity"],
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"roles": "s3-admin"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"attachedPolicies": ["S3AdminPolicy"],
|
|
"description": "Full S3 administrator access role"
|
|
},
|
|
{
|
|
"roleName": "S3ReadOnlyRole",
|
|
"roleArn": "arn:seaweed:iam::role/S3ReadOnlyRole",
|
|
"trustPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": {
|
|
"Federated": "keycloak-oidc"
|
|
},
|
|
"Action": ["sts:AssumeRoleWithWebIdentity"],
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"roles": "s3-read-only"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"attachedPolicies": ["S3ReadOnlyPolicy"],
|
|
"description": "Read-only access to S3 resources"
|
|
},
|
|
{
|
|
"roleName": "S3ReadWriteRole",
|
|
"roleArn": "arn:seaweed:iam::role/S3ReadWriteRole",
|
|
"trustPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": {
|
|
"Federated": "keycloak-oidc"
|
|
},
|
|
"Action": ["sts:AssumeRoleWithWebIdentity"],
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"roles": "s3-read-write"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"attachedPolicies": ["S3ReadWritePolicy"],
|
|
"description": "Read-write access to S3 resources"
|
|
}
|
|
],
|
|
"policies": [
|
|
{
|
|
"name": "S3AdminPolicy",
|
|
"document": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "s3:*",
|
|
"Resource": "*"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"name": "S3ReadOnlyPolicy",
|
|
"document": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"s3:GetObject",
|
|
"s3:GetObjectAcl",
|
|
"s3:GetObjectVersion",
|
|
"s3:ListBucket",
|
|
"s3:ListBucketVersions"
|
|
],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*",
|
|
"arn:seaweed:s3:::*/*"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"name": "S3ReadWritePolicy",
|
|
"document": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"s3:GetObject",
|
|
"s3:GetObjectAcl",
|
|
"s3:GetObjectVersion",
|
|
"s3:PutObject",
|
|
"s3:PutObjectAcl",
|
|
"s3:DeleteObject",
|
|
"s3:ListBucket",
|
|
"s3:ListBucketVersions"
|
|
],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*",
|
|
"arn:seaweed:s3:::*/*"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|