Skip to content

feat(s3): add write-only, no-delete S3 role support#37

Open
deepak7340 wants to merge 1 commit into
masterfrom
feat/s3-write-only-roles
Open

feat(s3): add write-only, no-delete S3 role support#37
deepak7340 wants to merge 1 commit into
masterfrom
feat/s3-write-only-roles

Conversation

@deepak7340

Copy link
Copy Markdown
Contributor

Adds a third role type alongside admin (roles) and read_only_roles: write_only_roles, which grants only s3:PutObject on specific buckets owned by another account, with no read/list/delete access.

@deepak7340
deepak7340 force-pushed the feat/s3-write-only-roles branch 22 times, most recently from a7d1d31 to 5e52443 Compare July 23, 2026 11:57
Replaces role::storage::s3::roles / read_only_roles / write_only_roles
with a single role::storage::s3::roles hash. bucket_access (formerly
buckets) is optional - omit it entirely for an account with nothing to
declare (e.g. a plain identity that only ever acts as another entry's
managed_by). Every bucket_access entry names managed_by explicitly -
the account whose credentials get borrowed to apply that bucket's
policy, since PutBucketPolicy has to be authenticated as an account
with rights over the bucket. managed_by must match a declared account
name, otherwise that entry is skipped with a warning.

Grant levels per bucket_access entry (the role field): read (GetObject
+ ListBucket), write (PutObject + ListBucket + GetBucketVersioning, no
GetObject), readwrite (write plus GetObject - needed by replication
clients like RustFS that HEAD/GET the destination object before
uploading), and admin (s3:* - the broadest grant, not a claim of
ownership; managed_by still names whose credentials apply it).

adminAccounts in s3-sideloader-config.json lists every account in
roles: unconditionally again (not just ones referenced via
managed_by) - these accounts are needed there regardless of whether
anything currently points at them as an owner.

Eit_types::Storage::S3::Account is replaced by
Eit_types::Storage::S3::Role.

Breaking change: existing hiera using the old format needs migrating
to the new roles: shape (buckets -> bucket_access, policy -> role,
use_policy -> managed_by) before this is applied.
@deepak7340
deepak7340 force-pushed the feat/s3-write-only-roles branch from 08c403e to 9a5b843 Compare July 23, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant