Basic ACL restrictions on Extended ACL #5
Labels
No labels
P0
P1
P2
P3
good first issue
triage
Infrastructure
blocked
bug
config
discussion
documentation
duplicate
enhancement
go
help wanted
internal
invalid
kludge
observability
perfomance
question
refactoring
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: TrueCloudLab/frostfs-api#5
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Basic ACL has some restrictions, so the user can't deny system requests like
object.Head
orobject.RangeHash
. This is required to keep system processes running e.g. object replication.Extended ACL can override those restriction which doesn't seem right to me. Restricted
object.Head
request will always fail replication check and produce extra work on replicator mechanism./cc @carpawell
Will be fixed by new policy handling mechanics in future versions.