mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-06 06:22:05 +02:00
* s3: restrict admin gRPC to local callers when no signing key The S3 gateway's gRPC port (default 0.0.0.0:19000, always on) serves the IAM cache and internal lifecycle admin services. checkAdminAuth was a no-op when jwt.filer_signing.key was unset, so any reachable host could PutIdentity an admin identity and take over the bucket data. Without a shared key callers cannot be distinguished, so admin RPCs are now limited to unix-socket, loopback, and the server's own interface addresses. Remote filer-to-S3 propagation and lifecycle workers must set jwt.filer_signing.key; the Bearer-token path is unchanged. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3: fail closed on nil guard and refresh local addresses per call Review feedback: a nil filerGuard bypassed all checks — treat it like a missing key and require a local peer. The own-address set was cached forever, so interfaces added later were rejected; enumerate per call instead since admin RPCs are rare. Nil ctx is denied rather than panics. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3: read the signing key once and bound interface enumeration Review feedback: reading SigningKey twice could straddle a SIGHUP reload — an old nonempty key skipped the local-peer check while the new empty key verified the token. And enumerating interfaces per no-key call is wasteful for co-located workers dialing the announced address; cache the address set for 30s so new interfaces still become usable promptly. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3: enumerate interface addresses per no-key admin call A cached address set keeps trusting an IP after it is removed from the host and reassigned to another machine — that host would then hold unauthenticated admin access for the cache TTL. Per-call enumeration only runs for non-loopback TCP peers on the no-key path, which is low-volume admin traffic, so the freshness is worth the syscall. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
238 lines
8.4 KiB
Go
238 lines
8.4 KiB
Go
package s3api
|
|
|
|
import (
|
|
"context"
|
|
"net"
|
|
"strings"
|
|
|
|
"github.com/seaweedfs/seaweedfs/weed/glog"
|
|
"github.com/seaweedfs/seaweedfs/weed/pb/iam_pb"
|
|
"github.com/seaweedfs/seaweedfs/weed/security"
|
|
"google.golang.org/grpc/codes"
|
|
"google.golang.org/grpc/metadata"
|
|
"google.golang.org/grpc/peer"
|
|
"google.golang.org/grpc/status"
|
|
)
|
|
|
|
// SeaweedS3IamCacheServer Implementation
|
|
// This interface is dedicated to UNIDIRECTIONAL updates from Filer to S3 Server.
|
|
// S3 Server acts purely as a cache.
|
|
|
|
// checkAdminAuth verifies the caller presented a Bearer token signed by the
|
|
// filer write-signing key (jwt.filer_signing.key). It mirrors the filer's
|
|
// IamGrpcServer.checkAdminAuth so the same operator knob that locks down the
|
|
// filer IAM gRPC service also locks down this cache. With no key configured
|
|
// remote callers cannot be told apart, so only local clients (unix socket,
|
|
// loopback, or the server's own addresses) are allowed.
|
|
func (s3a *S3ApiServer) checkAdminAuth(ctx context.Context) error {
|
|
var signingKey security.SigningKey
|
|
if s3a.filerGuard != nil {
|
|
signingKey = s3a.filerGuard.SigningKey()
|
|
}
|
|
if len(signingKey) == 0 {
|
|
return checkLocalPeer(ctx)
|
|
}
|
|
md, ok := metadata.FromIncomingContext(ctx)
|
|
if !ok {
|
|
return status.Error(codes.Unauthenticated, "missing metadata")
|
|
}
|
|
authHeaders := md.Get("authorization")
|
|
if len(authHeaders) == 0 {
|
|
return status.Error(codes.Unauthenticated, "missing authorization metadata")
|
|
}
|
|
raw := strings.TrimSpace(authHeaders[0])
|
|
parts := strings.Fields(raw)
|
|
if len(parts) != 2 || !strings.EqualFold(parts[0], "Bearer") || parts[1] == "" {
|
|
return status.Error(codes.Unauthenticated, "authorization header must use Bearer scheme")
|
|
}
|
|
parsed, err := security.DecodeJwt(signingKey, security.EncodedJwt(parts[1]), &security.SeaweedFilerAdminClaims{})
|
|
if err != nil || parsed == nil || !parsed.Valid {
|
|
return status.Error(codes.Unauthenticated, "invalid admin token")
|
|
}
|
|
if claims, ok := parsed.Claims.(*security.SeaweedFilerAdminClaims); !ok || claims.SessionId != "" {
|
|
return status.Error(codes.Unauthenticated, "invalid admin token")
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func checkLocalPeer(ctx context.Context) error {
|
|
if ctx == nil {
|
|
return status.Error(codes.Unauthenticated, "admin gRPC calls require jwt.filer_signing.key or a local client")
|
|
}
|
|
pr, ok := peer.FromContext(ctx)
|
|
if !ok {
|
|
return status.Error(codes.Unauthenticated, "admin gRPC calls require jwt.filer_signing.key or a local client")
|
|
}
|
|
if _, isUnix := pr.Addr.(*net.UnixAddr); isUnix {
|
|
return nil
|
|
}
|
|
var ip net.IP
|
|
if tcpAddr, ok := pr.Addr.(*net.TCPAddr); ok {
|
|
ip = tcpAddr.IP
|
|
} else if h, _, err := net.SplitHostPort(pr.Addr.String()); err == nil {
|
|
ip = net.ParseIP(h)
|
|
} else {
|
|
ip = net.ParseIP(pr.Addr.String())
|
|
}
|
|
if ip != nil && (ip.IsLoopback() || isLocalAddress(ip)) {
|
|
return nil
|
|
}
|
|
glog.V(1).Infof("rejected unauthenticated admin gRPC call from %s: no jwt.filer_signing.key configured", pr.Addr)
|
|
return status.Error(codes.Unauthenticated, "admin gRPC calls require jwt.filer_signing.key or a local client")
|
|
}
|
|
|
|
// isLocalAddress enumerates interfaces per call: only reachable for
|
|
// non-loopback TCP peers on the no-key admin path, which is low-volume —
|
|
// and a cached set would keep trusting an address after it is removed from
|
|
// the host and reassigned.
|
|
func isLocalAddress(ip net.IP) bool {
|
|
addrs, err := net.InterfaceAddrs()
|
|
if err != nil {
|
|
return false
|
|
}
|
|
for _, a := range addrs {
|
|
if ipNet, ok := a.(*net.IPNet); ok && ipNet.IP.Equal(ip) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func (s3a *S3ApiServer) PutIdentity(ctx context.Context, req *iam_pb.PutIdentityRequest) (*iam_pb.PutIdentityResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.Identity == nil {
|
|
return nil, status.Errorf(codes.InvalidArgument, "identity is required")
|
|
}
|
|
glog.V(1).Infof("IAM: received identity update for %s", req.Identity.Name)
|
|
if err := s3a.iam.UpsertIdentity(req.Identity); err != nil {
|
|
glog.Errorf("failed to update identity cache for %s: %v", req.Identity.Name, err)
|
|
return nil, status.Errorf(codes.Internal, "failed to update identity cache: %v", err)
|
|
}
|
|
return &iam_pb.PutIdentityResponse{}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) RemoveIdentity(ctx context.Context, req *iam_pb.RemoveIdentityRequest) (*iam_pb.RemoveIdentityResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.Username == "" {
|
|
return nil, status.Errorf(codes.InvalidArgument, "username is required")
|
|
}
|
|
glog.V(1).Infof("IAM: received identity removal for %s", req.Username)
|
|
s3a.iam.RemoveIdentity(req.Username)
|
|
return &iam_pb.RemoveIdentityResponse{}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) PutPolicy(ctx context.Context, req *iam_pb.PutPolicyRequest) (*iam_pb.PutPolicyResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.Name == "" {
|
|
return nil, status.Errorf(codes.InvalidArgument, "policy name is required")
|
|
}
|
|
if req.Content == "" {
|
|
return nil, status.Errorf(codes.InvalidArgument, "policy content is required")
|
|
}
|
|
|
|
glog.V(1).Infof("IAM: received policy update for %s", req.Name)
|
|
if s3a.iam == nil {
|
|
return nil, status.Errorf(codes.Internal, "IAM not initialized")
|
|
}
|
|
|
|
if err := s3a.iam.PutPolicy(req.Name, req.Content); err != nil {
|
|
glog.Errorf("failed to update policy cache for %s: %v", req.Name, err)
|
|
return nil, status.Errorf(codes.Internal, "failed to update policy cache: %v", err)
|
|
}
|
|
return &iam_pb.PutPolicyResponse{}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) DeletePolicy(ctx context.Context, req *iam_pb.DeletePolicyRequest) (*iam_pb.DeletePolicyResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.Name == "" {
|
|
return nil, status.Errorf(codes.InvalidArgument, "policy name is required")
|
|
}
|
|
|
|
glog.V(1).Infof("IAM: received policy removal for %s", req.Name)
|
|
if s3a.iam == nil {
|
|
return nil, status.Errorf(codes.Internal, "IAM not initialized")
|
|
}
|
|
|
|
if err := s3a.iam.DeletePolicy(req.Name); err != nil {
|
|
glog.Errorf("failed to delete policy cache for %s: %v", req.Name, err)
|
|
return nil, status.Errorf(codes.Internal, "failed to delete policy cache: %v", err)
|
|
}
|
|
return &iam_pb.DeletePolicyResponse{}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) GetPolicy(ctx context.Context, req *iam_pb.GetPolicyRequest) (*iam_pb.GetPolicyResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.Name == "" {
|
|
return nil, status.Errorf(codes.InvalidArgument, "policy name is required")
|
|
}
|
|
if s3a.iam == nil {
|
|
return nil, status.Errorf(codes.Internal, "IAM not initialized")
|
|
}
|
|
policy, err := s3a.iam.GetPolicy(req.Name)
|
|
if err != nil {
|
|
return &iam_pb.GetPolicyResponse{}, nil // Not found is fine for cache
|
|
}
|
|
return &iam_pb.GetPolicyResponse{
|
|
Name: policy.Name,
|
|
Content: policy.Content,
|
|
}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) PutGroup(ctx context.Context, req *iam_pb.PutGroupRequest) (*iam_pb.PutGroupResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.Group == nil {
|
|
return nil, status.Errorf(codes.InvalidArgument, "group is required")
|
|
}
|
|
glog.V(1).Infof("IAM: received group update for %s", req.Group.Name)
|
|
if s3a.iam == nil {
|
|
return nil, status.Errorf(codes.Internal, "IAM not initialized")
|
|
}
|
|
if err := s3a.iam.PutGroup(req.Group); err != nil {
|
|
glog.Errorf("failed to update group cache for %s: %v", req.Group.Name, err)
|
|
return nil, status.Errorf(codes.Internal, "failed to update group cache: %v", err)
|
|
}
|
|
return &iam_pb.PutGroupResponse{}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) RemoveGroup(ctx context.Context, req *iam_pb.RemoveGroupRequest) (*iam_pb.RemoveGroupResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
if req.GroupName == "" {
|
|
return nil, status.Errorf(codes.InvalidArgument, "group name is required")
|
|
}
|
|
glog.V(1).Infof("IAM: received group removal for %s", req.GroupName)
|
|
if s3a.iam == nil {
|
|
return nil, status.Errorf(codes.Internal, "IAM not initialized")
|
|
}
|
|
s3a.iam.RemoveGroup(req.GroupName)
|
|
return &iam_pb.RemoveGroupResponse{}, nil
|
|
}
|
|
|
|
func (s3a *S3ApiServer) ListPolicies(ctx context.Context, req *iam_pb.ListPoliciesRequest) (*iam_pb.ListPoliciesResponse, error) {
|
|
if err := s3a.checkAdminAuth(ctx); err != nil {
|
|
return nil, err
|
|
}
|
|
resp := &iam_pb.ListPoliciesResponse{}
|
|
if s3a.iam == nil {
|
|
return nil, status.Errorf(codes.Internal, "IAM not initialized")
|
|
}
|
|
policies := s3a.iam.ListPolicies()
|
|
for _, policy := range policies {
|
|
resp.Policies = append(resp.Policies, policy)
|
|
}
|
|
return resp, nil
|
|
}
|