mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-11 00:50:43 +02:00
* iamapi: route managed policies through credential manager (fixes #9518) CreatePolicy via the IAM API wrote straight to the filer /etc/iam/policies.json, ignoring any non-filer credential store. When credential.postgres was configured, policies created via the IAM API landed only in the filer while the Admin UI wrote to postgres, producing a split-brain where ListPolicies/GetPolicy never saw the Admin UI's policies and vice versa. GetPolicies/PutPolicies on IamS3ApiConfigure now load managed policies from credentialManager and persist Create/Update/Delete as a delta against the store. Inline user/group policies still live in the legacy policies.json file (no credential-store API for them yet). Pre-existing managed policies in the legacy file are merged on read so deployments don't lose data, and re-persisted to the store on the next write so the legacy file is drained over time. * credential: route IAM API inline policies through credential manager Extends the #9518 fix to user-inline and group-inline policies so the IAM API never writes the legacy /etc/iam/policies.json bundle directly. The previous patch only routed managed policies; this one finishes the job for the other two policy types. - Add GroupInlinePolicyStore + GroupInlinePoliciesLoader optional interfaces, mirroring the existing user-inline ones, and matching Put/Get/Delete/List/LoadAll wrappers on CredentialManager. - Implement group-inline storage in memory (new map), filer_etc (new field on PoliciesCollection, reusing the legacy file under policyMu), and postgres (new group_inline_policies table with ON DELETE CASCADE off the groups FK). - Wire the new methods through PropagatingCredentialStore so wrapped stores still delegate correctly. - IamS3ApiConfigure.PutPolicies now applies managed + user-inline + group-inline as deltas through the credential manager; the legacy /etc/iam/policies.json file is never written when a credential manager is wired up. GetPolicies still reads the legacy bundle once as a fallback so unmigrated data is picked up and re-persisted into the store on the next write. * credential: propagate SaveConfiguration writes to running S3 caches Postgres (and any non-filer) credential stores never fired the S3 IAM cache invalidation path on bulk identity / group updates. The PropagatingCredentialStore had explicit Put/Remove handlers for single-entity calls (CreateUser, PutPolicy, etc.) but inherited SaveConfiguration unchanged from the embedded store, so the bulk path the IAM API takes at the end of every handler was silent. Inline-policy changes recompute identity.Actions and persist via SaveConfiguration, so until restart the cached Actions on each S3 server stayed stale and authorization decisions used the pre-change view. Override SaveConfiguration to snapshot the prior user / group lists, delegate the save, then fan out PutIdentity / PutGroup for what's in the new config and RemoveIdentity / RemoveGroup for what got pruned. Reuses the existing SeaweedS3IamCache RPCs, no protobuf changes. * iamapi: drain legacy policies.json after authoritative credential-store writes Review pointed out a resurrection bug: GetPolicies still reads /etc/iam/policies.json as a one-way migration fallback, but PutPolicies in the credential-manager path never wrote that file, so legacy-only entries reappeared on the next read even after the IAM API "deleted" them. PutPolicies now overwrites the bundle with an empty {} after a successful credential-store write, unless the store is filer_etc (which owns the bundle as its own inline-policy backing — clearing it would wipe filer_etc's data). Also wraps the filer read, JSON unmarshal, and marshal errors with context per the other review comments.
65 lines
2.4 KiB
Go
65 lines
2.4 KiB
Go
package credential_test
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
|
|
"github.com/seaweedfs/seaweedfs/weed/credential"
|
|
"github.com/seaweedfs/seaweedfs/weed/credential/memory"
|
|
"github.com/seaweedfs/seaweedfs/weed/pb/iam_pb"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
|
|
// Side-effect: register filer_etc so the existing
|
|
// TestCredentialStoreInterface / TestGetAvailableStores assertions
|
|
// (which expect filer_etc to always be present) stay satisfied now
|
|
// that this test file pulls in `memory` and the `len(Stores) == 0`
|
|
// skip path no longer fires.
|
|
_ "github.com/seaweedfs/seaweedfs/weed/credential/filer_etc"
|
|
)
|
|
|
|
// TestSaveConfigurationDelegatesWithoutMaster confirms the override delegates
|
|
// to the underlying store and the no-master fan-out path is a safe no-op.
|
|
// propagateChange already short-circuits when masterClient is nil, so we
|
|
// don't need to spin up a fake S3 IAM cache server here.
|
|
func TestSaveConfigurationDelegatesWithoutMaster(t *testing.T) {
|
|
ctx := context.Background()
|
|
upstream := &memory.MemoryStore{}
|
|
require.NoError(t, upstream.Initialize(nil, ""))
|
|
|
|
ps := credential.NewPropagatingCredentialStore(upstream, nil, nil)
|
|
|
|
cfg := &iam_pb.S3ApiConfiguration{
|
|
Identities: []*iam_pb.Identity{{Name: "alice"}, {Name: "bob"}},
|
|
}
|
|
require.NoError(t, ps.SaveConfiguration(ctx, cfg))
|
|
|
|
users, err := upstream.ListUsers(ctx)
|
|
require.NoError(t, err)
|
|
assert.ElementsMatch(t, []string{"alice", "bob"}, users)
|
|
}
|
|
|
|
// TestSaveConfigurationDiffSnapshotTakenBeforeWrite confirms that deletions
|
|
// the underlying SaveConfiguration prunes are visible to the propagation
|
|
// diff. We replay a second SaveConfiguration that drops "bob" and verify the
|
|
// underlying store reflects the deletion (the propagation fan-out is a
|
|
// no-op without masterClient but the diff snapshot pathway runs).
|
|
func TestSaveConfigurationDiffSnapshotTakenBeforeWrite(t *testing.T) {
|
|
ctx := context.Background()
|
|
upstream := &memory.MemoryStore{}
|
|
require.NoError(t, upstream.Initialize(nil, ""))
|
|
|
|
ps := credential.NewPropagatingCredentialStore(upstream, nil, nil)
|
|
|
|
require.NoError(t, ps.SaveConfiguration(ctx, &iam_pb.S3ApiConfiguration{
|
|
Identities: []*iam_pb.Identity{{Name: "alice"}, {Name: "bob"}},
|
|
}))
|
|
require.NoError(t, ps.SaveConfiguration(ctx, &iam_pb.S3ApiConfiguration{
|
|
Identities: []*iam_pb.Identity{{Name: "alice"}},
|
|
}))
|
|
|
|
users, err := upstream.ListUsers(ctx)
|
|
require.NoError(t, err)
|
|
assert.ElementsMatch(t, []string{"alice"}, users)
|
|
}
|