mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-09 07:47:54 +02:00
refactor: Enhance existing NewS3ApiServer instead of creating separate IAM function
- Add IamConfig field to S3ApiServerOption for optional advanced IAM - Integrate IAM loading logic directly into NewS3ApiServerWithStore - Remove duplicate enhanced_s3_server.go file - Simplify command line logic to use single server constructor - Maintain backward compatibility - standard IAM works without config - Advanced IAM activated automatically when -iam.config is provided This follows better architectural principles by enhancing existing functions rather than creating parallel implementations.
This commit is contained in:
1 parent
299c86f002
commit
4c324fca15
3 files changed
+101
-199
No files matched your search
@@ -2,15 +2,20 @@ package s3api
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net"
|
||||
"net/http"
|
||||
"os"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/seaweedfs/seaweedfs/weed/credential"
|
||||
"github.com/seaweedfs/seaweedfs/weed/filer"
|
||||
"github.com/seaweedfs/seaweedfs/weed/glog"
|
||||
"github.com/seaweedfs/seaweedfs/weed/iam/integration"
|
||||
"github.com/seaweedfs/seaweedfs/weed/iam/policy"
|
||||
"github.com/seaweedfs/seaweedfs/weed/iam/sts"
|
||||
"github.com/seaweedfs/seaweedfs/weed/pb/s3_pb"
|
||||
"github.com/seaweedfs/seaweedfs/weed/util/grace"
|
||||
|
||||
@@ -38,12 +43,14 @@ type S3ApiServerOption struct {
|
||||
LocalFilerSocket string
|
||||
DataCenter string
|
||||
FilerGroup string
|
||||
IamConfig string // Advanced IAM configuration file path
|
||||
}
|
||||
|
||||
type S3ApiServer struct {
|
||||
s3_pb.UnimplementedSeaweedS3Server
|
||||
option *S3ApiServerOption
|
||||
iam *IdentityAccessManagement
|
||||
iamIntegration *S3IAMIntegration // Advanced IAM integration for JWT authentication
|
||||
cb *CircuitBreaker
|
||||
randomClientId int32
|
||||
filerGuard *security.Guard
|
||||
@@ -91,6 +98,27 @@ func NewS3ApiServerWithStore(router *mux.Router, option *S3ApiServerOption, expl
|
||||
bucketConfigCache: NewBucketConfigCache(60 * time.Minute), // Increased TTL since cache is now event-driven
|
||||
}
|
||||
|
||||
// Initialize advanced IAM system if config is provided
|
||||
if option.IamConfig != "" {
|
||||
glog.V(0).Infof("Loading advanced IAM configuration from: %s", option.IamConfig)
|
||||
|
||||
iamManager, err := loadIAMManagerFromConfig(option.IamConfig)
|
||||
if err != nil {
|
||||
glog.Errorf("Failed to load IAM configuration: %v", err)
|
||||
} else {
|
||||
// Create S3 IAM integration with the loaded IAM manager
|
||||
s3iam := NewS3IAMIntegration(iamManager)
|
||||
|
||||
// Set IAM integration in server
|
||||
s3ApiServer.iamIntegration = s3iam
|
||||
|
||||
// Set the integration in the traditional IAM for compatibility
|
||||
iam.SetIAMIntegration(s3iam)
|
||||
|
||||
glog.V(0).Infof("Advanced IAM system initialized successfully")
|
||||
}
|
||||
}
|
||||
|
||||
if option.Config != "" {
|
||||
grace.OnReload(func() {
|
||||
if err := s3ApiServer.iam.loadS3ApiConfigurationFromFile(option.Config); err != nil {
|
||||
@@ -382,3 +410,58 @@ func (s3a *S3ApiServer) registerRouter(router *mux.Router) {
|
||||
apiRouter.NotFoundHandler = http.HandlerFunc(s3err.NotFoundHandler)
|
||||
|
||||
}
|
||||
|
||||
// loadIAMManagerFromConfig loads the advanced IAM manager from configuration file
|
||||
func loadIAMManagerFromConfig(configPath string) (*integration.IAMManager, error) {
|
||||
// Read configuration file
|
||||
configData, err := os.ReadFile(configPath)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to read config file: %w", err)
|
||||
}
|
||||
|
||||
// Parse configuration structure
|
||||
var configRoot struct {
|
||||
STS *sts.STSConfig `json:"sts"`
|
||||
Policy *policy.PolicyEngineConfig `json:"policy"`
|
||||
Providers []map[string]interface{} `json:"providers"`
|
||||
Roles []*integration.RoleDefinition `json:"roles"`
|
||||
Policies []struct {
|
||||
Name string `json:"name"`
|
||||
Document *policy.PolicyDocument `json:"document"`
|
||||
} `json:"policies"`
|
||||
}
|
||||
|
||||
if err := json.Unmarshal(configData, &configRoot); err != nil {
|
||||
return nil, fmt.Errorf("failed to parse config: %w", err)
|
||||
}
|
||||
|
||||
// Create IAM configuration
|
||||
iamConfig := &integration.IAMConfig{
|
||||
STS: configRoot.STS,
|
||||
Policy: configRoot.Policy,
|
||||
}
|
||||
|
||||
// Initialize IAM manager
|
||||
iamManager := integration.NewIAMManager()
|
||||
if err := iamManager.Initialize(iamConfig); err != nil {
|
||||
return nil, fmt.Errorf("failed to initialize IAM manager: %w", err)
|
||||
}
|
||||
|
||||
// Load policies
|
||||
for _, policyDef := range configRoot.Policies {
|
||||
if err := iamManager.CreatePolicy(context.Background(), policyDef.Name, policyDef.Document); err != nil {
|
||||
glog.Warningf("Failed to create policy %s: %v", policyDef.Name, err)
|
||||
}
|
||||
}
|
||||
|
||||
// Load roles
|
||||
for _, roleDef := range configRoot.Roles {
|
||||
if err := iamManager.CreateRole(context.Background(), roleDef.RoleName, roleDef); err != nil {
|
||||
glog.Warningf("Failed to create role %s: %v", roleDef.RoleName, err)
|
||||
}
|
||||
}
|
||||
|
||||
glog.V(0).Infof("Loaded %d policies and %d roles from config", len(configRoot.Policies), len(configRoot.Roles))
|
||||
|
||||
return iamManager, nil
|
||||
}
|
||||
Reference in new issue
Block a user