mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-09 07:47:54 +02:00
refactor: simplify configuration by using constants for default base paths
This commit addresses the user feedback that configuration files should not
need to specify default paths when constants are available.
### Changes Made:
#### Configuration Simplification:
- Removed redundant basePath configurations from iam_config_distributed.json
- All stores now use constants for defaults:
* Sessions: /etc/iam/sessions (DefaultSessionBasePath)
* Policies: /etc/iam/policies (DefaultPolicyBasePath)
* Roles: /etc/iam/roles (DefaultRoleBasePath)
- Eliminated empty storeConfig objects entirely for cleaner JSON
#### Updated Store Implementations:
- FilerPolicyStore: Updated hardcoded path to use /etc/iam/policies
- FilerRoleStore: Updated hardcoded path to use /etc/iam/roles
- All stores consistently align with /etc/ filer convention
#### Runtime Filer Address Integration:
- Updated IAM manager methods to accept filerAddress parameter:
* AssumeRoleWithWebIdentity(ctx, filerAddress, request)
* AssumeRoleWithCredentials(ctx, filerAddress, request)
* IsActionAllowed(ctx, filerAddress, request)
* ExpireSessionForTesting(ctx, filerAddress, sessionToken)
- Enhanced S3IAMIntegration to store filerAddress from S3ApiServer
- Updated all test files to pass test filerAddress ('localhost:8888')
### Benefits:
- ✅ Cleaner, minimal configuration files
- ✅ Consistent use of well-defined constants for defaults
- ✅ No configuration needed for standard use cases
- ✅ Runtime filer address flexibility maintained
- ✅ Aligns with SeaweedFS /etc/ convention throughout
### Breaking Change:
- S3IAMIntegration constructor now requires filerAddress parameter
- All IAM manager methods now require filerAddress as second parameter
- Tests and middleware updated accordingly
This commit is contained in:
1 parent
e0b284d2fe
commit
586ebbca2d
8 files changed
+33
-40
No files matched your search
@@ -84,7 +84,7 @@ func TestS3EndToEndWithJWT(t *testing.T) {
|
||||
tt.setupRole(ctx, iamManager)
|
||||
|
||||
// Assume role to get JWT token
|
||||
response, err := iamManager.AssumeRoleWithWebIdentity(ctx, &sts.AssumeRoleWithWebIdentityRequest{
|
||||
response, err := iamManager.AssumeRoleWithWebIdentity(ctx, "localhost:8888", &sts.AssumeRoleWithWebIdentityRequest{
|
||||
RoleArn: tt.roleArn,
|
||||
WebIdentityToken: "valid-oidc-token",
|
||||
RoleSessionName: tt.sessionName,
|
||||
|
||||
@@ -16,15 +16,17 @@ import (
|
||||
|
||||
// S3IAMIntegration provides IAM integration for S3 API
|
||||
type S3IAMIntegration struct {
|
||||
iamManager *integration.IAMManager
|
||||
enabled bool
|
||||
iamManager *integration.IAMManager
|
||||
filerAddress string
|
||||
enabled bool
|
||||
}
|
||||
|
||||
// NewS3IAMIntegration creates a new S3 IAM integration
|
||||
func NewS3IAMIntegration(iamManager *integration.IAMManager) *S3IAMIntegration {
|
||||
func NewS3IAMIntegration(iamManager *integration.IAMManager, filerAddress string) *S3IAMIntegration {
|
||||
return &S3IAMIntegration{
|
||||
iamManager: iamManager,
|
||||
enabled: iamManager != nil,
|
||||
iamManager: iamManager,
|
||||
filerAddress: filerAddress,
|
||||
enabled: iamManager != nil,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -93,7 +95,7 @@ func (s3iam *S3IAMIntegration) AuthenticateJWT(ctx context.Context, r *http.Requ
|
||||
}
|
||||
|
||||
glog.V(0).Infof("AuthenticateJWT: calling IsActionAllowed for principal=%s", principalArn)
|
||||
allowed, err := s3iam.iamManager.IsActionAllowed(ctx, testRequest)
|
||||
allowed, err := s3iam.iamManager.IsActionAllowed(ctx, s3iam.filerAddress, testRequest)
|
||||
glog.V(0).Infof("AuthenticateJWT: IsActionAllowed returned allowed=%t, err=%v", allowed, err)
|
||||
if err != nil || !allowed {
|
||||
glog.V(0).Infof("IAM validation failed for %s: %v", principalArn, err)
|
||||
@@ -145,7 +147,7 @@ func (s3iam *S3IAMIntegration) AuthorizeAction(ctx context.Context, identity *IA
|
||||
}
|
||||
|
||||
// Check if action is allowed using our policy engine
|
||||
allowed, err := s3iam.iamManager.IsActionAllowed(ctx, actionRequest)
|
||||
allowed, err := s3iam.iamManager.IsActionAllowed(ctx, s3iam.filerAddress, actionRequest)
|
||||
if err != nil {
|
||||
// Log the error but treat authentication/authorization failures as access denied
|
||||
// rather than internal errors to provide better user experience
|
||||
|
||||
@@ -107,7 +107,7 @@ func NewS3ApiServerWithStore(router *mux.Router, option *S3ApiServerOption, expl
|
||||
glog.Errorf("Failed to load IAM configuration: %v", err)
|
||||
} else {
|
||||
// Create S3 IAM integration with the loaded IAM manager
|
||||
s3iam := NewS3IAMIntegration(iamManager)
|
||||
s3iam := NewS3IAMIntegration(iamManager, string(option.Filer))
|
||||
|
||||
// Set IAM integration in server
|
||||
s3ApiServer.iamIntegration = s3iam
|
||||
|
||||
Reference in new issue
Block a user