mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-08-20 06:07:05 +00:00
MAJOR ENHANCEMENT: Complete S3+IAM Integration Test Framework 🏆 COMPREHENSIVE TEST SUITE CREATED: - Full end-to-end S3 API testing with IAM authentication and authorization - JWT token-based authentication testing with OIDC provider simulation - Policy enforcement validation for read-only, write-only, and admin roles - Session management and expiration testing framework - Multipart upload IAM integration testing - Bucket policy integration and conflict resolution testing - Contextual policy enforcement (IP-based, time-based conditions) - Presigned URL generation with IAM validation ✅ COMPLETE TEST FRAMEWORK (10 FILES CREATED): - s3_iam_integration_test.go: Main integration test suite (17KB, 7 test functions) - s3_iam_framework.go: Test utilities and mock infrastructure (10KB) - Makefile: Comprehensive build and test automation (7KB, 20+ targets) - README.md: Complete documentation and usage guide (12KB) - test_config.json: IAM configuration for testing (8KB) - go.mod/go.sum: Dependency management with AWS SDK and JWT libraries - Dockerfile.test: Containerized testing environment - docker-compose.test.yml: Multi-service testing with LDAP support 🧪 TEST SCENARIOS IMPLEMENTED: 1. TestS3IAMAuthentication: Valid/invalid/expired JWT token handling 2. TestS3IAMPolicyEnforcement: Role-based access control validation 3. TestS3IAMSessionExpiration: Session lifecycle and expiration testing 4. TestS3IAMMultipartUploadPolicyEnforcement: Multipart operation IAM integration 5. TestS3IAMBucketPolicyIntegration: Resource-based policy testing 6. TestS3IAMContextualPolicyEnforcement: Conditional access control 7. TestS3IAMPresignedURLIntegration: Temporary access URL generation 🔧 TESTING INFRASTRUCTURE: - Mock OIDC Provider: In-memory OIDC server with JWT signing capabilities - RSA Key Generation: 2048-bit keys for secure JWT token signing - Service Lifecycle Management: Automatic SeaweedFS service startup/shutdown - Resource Cleanup: Automatic bucket and object cleanup after tests - Health Checks: Service availability monitoring and wait strategies �� AUTOMATION & CI/CD READY: - Make targets for individual test categories (auth, policy, expiration, etc.) - Docker support for containerized testing environments - CI/CD integration with GitHub Actions and Jenkins examples - Performance benchmarking capabilities with memory profiling - Watch mode for development with automatic test re-runs ✅ SERVICE INTEGRATION TESTING: - Master Server (9333): Cluster coordination and metadata management - Volume Server (8080): Object storage backend testing - Filer Server (8888): Metadata and IAM persistent storage testing - S3 API Server (8333): Complete S3-compatible API with IAM integration - Mock OIDC Server: Identity provider simulation for authentication testing 🎯 PRODUCTION-READY FEATURES: - Comprehensive error handling and assertion validation - Realistic test scenarios matching production use cases - Multiple authentication methods (JWT, session tokens, basic auth) - Policy conflict resolution testing (IAM vs bucket policies) - Concurrent operations testing with multiple clients - Security validation with proper access denial testing 🔒 ENTERPRISE TESTING CAPABILITIES: - Multi-tenant access control validation - Role-based permission inheritance testing - Session token expiration and renewal testing - IP-based and time-based conditional access testing - Audit trail validation for compliance testing - Load testing framework for performance validation 📋 DEVELOPER EXPERIENCE: - Comprehensive README with setup instructions and examples - Makefile with intuitive targets and help documentation - Debug mode for manual service inspection and troubleshooting - Log analysis tools and service health monitoring - Extensible framework for adding new test scenarios This provides a complete, production-ready testing framework for validating the advanced IAM integration with SeaweedFS S3 API functionality! Ready for comprehensive S3+IAM validation 🚀
335 lines
8.3 KiB
JSON
335 lines
8.3 KiB
JSON
{
|
|
"identities": [
|
|
{
|
|
"name": "testuser",
|
|
"credentials": [
|
|
{
|
|
"accessKey": "test-access-key",
|
|
"secretKey": "test-secret-key"
|
|
}
|
|
],
|
|
"actions": ["Admin"]
|
|
},
|
|
{
|
|
"name": "readonlyuser",
|
|
"credentials": [
|
|
{
|
|
"accessKey": "readonly-access-key",
|
|
"secretKey": "readonly-secret-key"
|
|
}
|
|
],
|
|
"actions": ["Read"]
|
|
},
|
|
{
|
|
"name": "writeonlyuser",
|
|
"credentials": [
|
|
{
|
|
"accessKey": "writeonly-access-key",
|
|
"secretKey": "writeonly-secret-key"
|
|
}
|
|
],
|
|
"actions": ["Write"]
|
|
}
|
|
],
|
|
"iam": {
|
|
"enabled": true,
|
|
"sts": {
|
|
"tokenDuration": "15m",
|
|
"issuer": "seaweedfs-sts",
|
|
"signingKey": "test-sts-signing-key-for-integration-tests"
|
|
},
|
|
"policy": {
|
|
"defaultEffect": "Deny"
|
|
},
|
|
"providers": {
|
|
"oidc": {
|
|
"test-oidc": {
|
|
"issuer": "http://localhost:8080/.well-known/openid_configuration",
|
|
"clientId": "test-client-id",
|
|
"jwksUri": "http://localhost:8080/jwks",
|
|
"userInfoUri": "http://localhost:8080/userinfo",
|
|
"roleMapping": {
|
|
"rules": [
|
|
{
|
|
"claim": "groups",
|
|
"claimValue": "admins",
|
|
"roleName": "S3AdminRole"
|
|
},
|
|
{
|
|
"claim": "groups",
|
|
"claimValue": "users",
|
|
"roleName": "S3ReadOnlyRole"
|
|
},
|
|
{
|
|
"claim": "groups",
|
|
"claimValue": "writers",
|
|
"roleName": "S3WriteOnlyRole"
|
|
}
|
|
]
|
|
},
|
|
"claimsMapping": {
|
|
"email": "email",
|
|
"displayName": "name",
|
|
"groups": "groups"
|
|
}
|
|
}
|
|
},
|
|
"ldap": {
|
|
"test-ldap": {
|
|
"server": "ldap://localhost:389",
|
|
"baseDN": "dc=example,dc=com",
|
|
"bindDN": "cn=admin,dc=example,dc=com",
|
|
"bindPassword": "admin-password",
|
|
"userFilter": "(uid=%s)",
|
|
"groupFilter": "(memberUid=%s)",
|
|
"attributes": {
|
|
"email": "mail",
|
|
"displayName": "cn",
|
|
"groups": "memberOf"
|
|
},
|
|
"roleMapping": {
|
|
"rules": [
|
|
{
|
|
"claim": "groups",
|
|
"claimValue": "cn=admins,ou=groups,dc=example,dc=com",
|
|
"roleName": "S3AdminRole"
|
|
},
|
|
{
|
|
"claim": "groups",
|
|
"claimValue": "cn=users,ou=groups,dc=example,dc=com",
|
|
"roleName": "S3ReadOnlyRole"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"sessionStore": {
|
|
"type": "filer",
|
|
"config": {
|
|
"filerAddress": "localhost:8888",
|
|
"basePath": "/seaweedfs/iam/sessions"
|
|
}
|
|
},
|
|
"policyStore": {
|
|
"type": "filer",
|
|
"config": {
|
|
"filerAddress": "localhost:8888",
|
|
"basePath": "/seaweedfs/iam/policies"
|
|
}
|
|
}
|
|
},
|
|
"roles": {
|
|
"S3AdminRole": {
|
|
"trustPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": {
|
|
"Federated": ["test-oidc", "test-ldap"]
|
|
},
|
|
"Action": "sts:AssumeRoleWithWebIdentity"
|
|
}
|
|
]
|
|
},
|
|
"attachedPolicies": ["S3AdminPolicy"],
|
|
"description": "Full administrative access to S3 resources"
|
|
},
|
|
"S3ReadOnlyRole": {
|
|
"trustPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": {
|
|
"Federated": ["test-oidc", "test-ldap"]
|
|
},
|
|
"Action": "sts:AssumeRoleWithWebIdentity"
|
|
}
|
|
]
|
|
},
|
|
"attachedPolicies": ["S3ReadOnlyPolicy"],
|
|
"description": "Read-only access to S3 resources"
|
|
},
|
|
"S3WriteOnlyRole": {
|
|
"trustPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Principal": {
|
|
"Federated": ["test-oidc", "test-ldap"]
|
|
},
|
|
"Action": "sts:AssumeRoleWithWebIdentity"
|
|
}
|
|
]
|
|
},
|
|
"attachedPolicies": ["S3WriteOnlyPolicy"],
|
|
"description": "Write-only access to S3 resources"
|
|
}
|
|
},
|
|
"policies": {
|
|
"S3AdminPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": ["s3:*"],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*",
|
|
"arn:seaweed:s3:::*/*"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"S3ReadOnlyPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"s3:GetObject",
|
|
"s3:GetObjectVersion",
|
|
"s3:ListBucket",
|
|
"s3:ListBucketVersions",
|
|
"s3:GetBucketLocation",
|
|
"s3:GetBucketVersioning"
|
|
],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*",
|
|
"arn:seaweed:s3:::*/*"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"S3WriteOnlyPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"s3:PutObject",
|
|
"s3:PutObjectAcl",
|
|
"s3:DeleteObject",
|
|
"s3:DeleteObjectVersion",
|
|
"s3:InitiateMultipartUpload",
|
|
"s3:UploadPart",
|
|
"s3:CompleteMultipartUpload",
|
|
"s3:AbortMultipartUpload",
|
|
"s3:ListMultipartUploadParts"
|
|
],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*/*"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"S3BucketManagementPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"s3:CreateBucket",
|
|
"s3:DeleteBucket",
|
|
"s3:GetBucketPolicy",
|
|
"s3:PutBucketPolicy",
|
|
"s3:DeleteBucketPolicy",
|
|
"s3:GetBucketVersioning",
|
|
"s3:PutBucketVersioning"
|
|
],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"S3IPRestrictedPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": ["s3:*"],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*",
|
|
"arn:seaweed:s3:::*/*"
|
|
],
|
|
"Condition": {
|
|
"IpAddress": {
|
|
"aws:SourceIp": ["192.168.1.0/24", "10.0.0.0/8"]
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"S3TimeBasedPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": ["s3:GetObject", "s3:ListBucket"],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::*",
|
|
"arn:seaweed:s3:::*/*"
|
|
],
|
|
"Condition": {
|
|
"DateGreaterThan": {
|
|
"aws:CurrentTime": "2023-01-01T00:00:00Z"
|
|
},
|
|
"DateLessThan": {
|
|
"aws:CurrentTime": "2025-12-31T23:59:59Z"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"bucketPolicyExamples": {
|
|
"PublicReadPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Sid": "PublicReadGetObject",
|
|
"Effect": "Allow",
|
|
"Principal": "*",
|
|
"Action": "s3:GetObject",
|
|
"Resource": "arn:seaweed:s3:::example-bucket/*"
|
|
}
|
|
]
|
|
},
|
|
"DenyDeletePolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Sid": "DenyDeleteOperations",
|
|
"Effect": "Deny",
|
|
"Principal": "*",
|
|
"Action": ["s3:DeleteObject", "s3:DeleteBucket"],
|
|
"Resource": [
|
|
"arn:seaweed:s3:::example-bucket",
|
|
"arn:seaweed:s3:::example-bucket/*"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"IPRestrictedAccessPolicy": {
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Sid": "IPRestrictedAccess",
|
|
"Effect": "Allow",
|
|
"Principal": "*",
|
|
"Action": ["s3:GetObject", "s3:PutObject"],
|
|
"Resource": "arn:seaweed:s3:::example-bucket/*",
|
|
"Condition": {
|
|
"IpAddress": {
|
|
"aws:SourceIp": ["203.0.113.0/24"]
|
|
}
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
}
|