Commit Graph

1322 Commits (29a2dae40cb7236a856e976a0522aa932239016f)

Author SHA1 Message Date
Denis Kirillov 29a2dae40c [#269] Move frostfsid client to separate package
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-17 12:11:23 +03:00
Denis Kirillov fec3b3f31e [#269] Add frostfsid cache configuration
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-17 12:11:23 +03:00
Denis Kirillov 7db89c840b [#368] Update vulnerable dependencies
/ DCO (pull_request) Successful in 3m41s Details
/ Vulncheck (pull_request) Successful in 3m28s Details
/ Builds (1.20) (pull_request) Successful in 4m41s Details
/ Builds (1.21) (pull_request) Successful in 4m35s Details
/ Lint (pull_request) Successful in 5m57s Details
/ Tests (1.20) (pull_request) Successful in 4m8s Details
/ Tests (1.21) (pull_request) Successful in 3m58s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-17 11:29:09 +03:00
Marina Biryukova 3ff027587c [#357] Add check of request and resource tags
Signed-off-by: Marina Biryukova <m.biryukova@yadro.com>
2024-04-17 07:06:58 +00:00
Denis Kirillov 9f29fcbd52 [#353] docs: Add bucket policy docs
/ DCO (pull_request) Successful in 1m35s Details
/ Builds (1.20) (pull_request) Successful in 2m12s Details
/ Builds (1.21) (pull_request) Successful in 1m51s Details
/ Vulncheck (pull_request) Failing after 2m8s Details
/ Lint (pull_request) Successful in 3m2s Details
/ Tests (1.20) (pull_request) Successful in 2m40s Details
/ Tests (1.21) (pull_request) Successful in 2m34s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-15 11:41:19 +03:00
Denis Kirillov 8307c73fef [#364] Fix removing combined object
/ Vulncheck (pull_request) Failing after 3m8s Details
/ DCO (pull_request) Successful in 3m49s Details
/ Builds (1.20) (pull_request) Successful in 5m35s Details
/ Builds (1.21) (pull_request) Successful in 4m16s Details
/ Lint (pull_request) Successful in 6m55s Details
/ Tests (1.20) (pull_request) Successful in 5m14s Details
/ Tests (1.21) (pull_request) Successful in 4m29s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-12 14:56:38 +03:00
Roman Loginov d8889fca56 [#340] Fix encode object acl
In the process of encode the acl of an object,
we use a map. As a result, when traversing the
map, we can get a different sequence of permissions
each time. Therefore, a list is used instead of a map.

Signed-off-by: Roman Loginov <r.loginov@yadro.com>
2024-04-11 09:28:30 +00:00
Alexey Vanin 61ff4702a2 [#360] Reuse single target during policy check
/ DCO (pull_request) Successful in 1m38s Details
/ Vulncheck (pull_request) Failing after 2m4s Details
/ Builds (1.20) (pull_request) Successful in 2m33s Details
/ Builds (1.21) (pull_request) Successful in 2m12s Details
/ Lint (pull_request) Successful in 3m6s Details
/ Tests (1.20) (pull_request) Successful in 2m57s Details
/ Tests (1.21) (pull_request) Successful in 2m6s Details
Policy engine library is able to manage multiple
targets and resolve different status results.

Signed-off-by: Alex Vanin <a.vanin@yadro.com>
2024-04-10 17:56:47 +03:00
Alexey Vanin 6da1acc554 [#360] Use 'c' prefix for bucket policies instead of 'n'
With 'c' prefix, acl chains become shorter, thus gateway
receives shorter results and avoids sessions to neo-go.

There is still issue with many IAM rules.

Signed-off-by: Alex Vanin <a.vanin@yadro.com>
2024-04-10 17:56:47 +03:00
Denis Kirillov 3ea3f971e1 [#359] Update APE to allow put tombstone on delete object
/ Vulncheck (pull_request) Failing after 4m0s Details
/ DCO (pull_request) Successful in 4m33s Details
/ Builds (1.20) (pull_request) Successful in 4m59s Details
/ Builds (1.21) (pull_request) Successful in 4m58s Details
/ Lint (pull_request) Successful in 6m17s Details
/ Tests (1.20) (pull_request) Successful in 4m57s Details
/ Tests (1.21) (pull_request) Successful in 4m7s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-10 15:12:30 +03:00
Alexey Vanin cb83f7646f [#347] port: Explicitly specify sorting order of subtree for object listing
/ DCO (pull_request) Successful in 1m56s Details
/ Vulncheck (pull_request) Failing after 4m57s Details
/ Builds (1.20) (pull_request) Successful in 5m54s Details
/ Builds (1.21) (pull_request) Successful in 5m56s Details
/ Lint (pull_request) Successful in 13m10s Details
/ Tests (1.20) (pull_request) Successful in 5m34s Details
/ Tests (1.21) (pull_request) Successful in 3m22s Details
Signed-off-by: Alex Vanin <a.vanin@yadro.com>
2024-04-09 18:57:47 +03:00
Denis Kirillov 9c012d0a66 [#355] Remove policies when delete bucket
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-09 15:49:46 +00:00
Denis Kirillov bda014b7b4 [#355] Update frostfs-contract to terminate session iterator
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-09 15:49:46 +00:00
Marina Biryukova 37d05dcefd [#353] Add check of listing parameters and versionID
/ DCO (pull_request) Successful in 1m36s Details
/ Vulncheck (pull_request) Failing after 2m17s Details
/ Builds (1.20) (pull_request) Successful in 3m27s Details
/ Builds (1.21) (pull_request) Successful in 3m22s Details
/ Lint (pull_request) Successful in 5m4s Details
/ Tests (1.20) (pull_request) Successful in 2m53s Details
/ Tests (1.21) (pull_request) Successful in 2m47s Details
Add properties in policy check:
* s3:delimiter
* s3:prefix
* s3:max-keys
* s3:VersionId

Signed-off-by: Marina Biryukova <m.biryukova@yadro.com>
2024-04-08 17:57:55 +03:00
Denis Kirillov 8407b3ea4c [#352] policy: Use iterators to list chains
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-04 12:51:12 +00:00
Alexey Vanin e537675223 [#341] Update CHANGELOG
Signed-off-by: Alex Vanin <a.vanin@yadro.com>
2024-04-03 12:04:48 +00:00
Alexey Vanin 789464e134 [#341] Add "h2" as next proto to allow HTTP/2 requests in http.Serve
Signed-off-by: Alex Vanin <a.vanin@yadro.com>
2024-04-03 12:04:48 +00:00
Alexey Vanin a138f4954b [#341] Test HTTP/2 requests
Signed-off-by: Alex Vanin <a.vanin@yadro.com>
2024-04-03 12:04:48 +00:00
Denis Kirillov 8669bf6b50 [#346] acl: Update APE and fix using
/ DCO (pull_request) Successful in 2m57s Details
/ Vulncheck (pull_request) Successful in 3m33s Details
/ Lint (pull_request) Successful in 4m44s Details
/ Tests (1.20) (pull_request) Successful in 3m38s Details
/ Tests (1.21) (pull_request) Successful in 3m29s Details
/ Builds (1.20) (pull_request) Successful in 1m12s Details
/ Builds (1.21) (pull_request) Successful in 3m23s Details
* Remove native policy when remove bucket policy
* Allow policies that contain only s3 compatible statements
(now deny rules cannot be converted to native rules)

Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-02 12:43:04 +00:00
Denis Kirillov 6b8095182e [#343] docs: Actualize s3 compatibility table
/ Builds (1.20) (pull_request) Successful in 13m52s Details
/ Builds (1.21) (pull_request) Successful in 13m40s Details
/ Lint (pull_request) Successful in 19m2s Details
/ Tests (1.20) (pull_request) Successful in 14m18s Details
/ Tests (1.21) (pull_request) Successful in 14m23s Details
/ DCO (pull_request) Successful in 2m55s Details
/ Vulncheck (pull_request) Successful in 1m9s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-04-02 15:02:51 +03:00
Denis Kirillov 348126b3b8 [#301] go.mod: Update sdk-go
/ Vulncheck (pull_request) Successful in 1m52s Details
/ Builds (1.20) (pull_request) Successful in 3m0s Details
/ Builds (1.21) (pull_request) Successful in 2m57s Details
/ DCO (pull_request) Successful in 2m50s Details
/ Lint (pull_request) Successful in 4m21s Details
/ Tests (1.20) (pull_request) Successful in 1m41s Details
/ Tests (1.21) (pull_request) Successful in 1m35s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-28 09:13:27 +03:00
Denis Kirillov fbe7a784e8 [#301] Support GetBucketPolicyStatus
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-28 09:13:25 +03:00
Pavel Pogodaev bfcde09f07 [#291] server auto re-binding
/ Vulncheck (pull_request) Failing after 1m38s Details
/ DCO (pull_request) Successful in 1m43s Details
/ Builds (1.20) (pull_request) Successful in 2m17s Details
/ Builds (1.21) (pull_request) Successful in 1m57s Details
/ Lint (pull_request) Successful in 5m7s Details
/ Tests (1.20) (pull_request) Successful in 2m32s Details
/ Tests (1.21) (pull_request) Successful in 2m8s Details
Signed-off-by: Pavel Pogodaev <p.pogodaev@yadro.com>
2024-03-27 14:28:50 +03:00
Denis Kirillov 94bd1dfe28 [#334] Add auth doc
/ DCO (pull_request) Successful in 1m18s Details
/ Vulncheck (pull_request) Failing after 1m42s Details
/ Builds (1.20) (pull_request) Successful in 2m16s Details
/ Builds (1.21) (pull_request) Successful in 1m51s Details
/ Lint (pull_request) Successful in 4m4s Details
/ Tests (1.20) (pull_request) Successful in 2m34s Details
/ Tests (1.21) (pull_request) Successful in 2m23s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-21 12:12:29 +03:00
Denis Kirillov 80c7b73eb9 [#306] In APE buckets forbid canned acl except private
/ DCO (pull_request) Successful in 2m50s Details
/ Vulncheck (pull_request) Failing after 3m15s Details
/ Builds (1.20) (pull_request) Successful in 3m39s Details
/ Builds (1.21) (pull_request) Successful in 3m41s Details
/ Lint (pull_request) Successful in 5m48s Details
/ Tests (1.20) (pull_request) Successful in 4m0s Details
/ Tests (1.21) (pull_request) Successful in 3m53s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-19 16:57:26 +03:00
Denis Kirillov 62cc5a04a7 [#328] Log error on failed response writing
/ DCO (pull_request) Successful in 3m34s Details
/ Vulncheck (pull_request) Failing after 4m18s Details
/ Builds (1.20) (pull_request) Successful in 4m58s Details
/ Builds (1.21) (pull_request) Successful in 4m24s Details
/ Lint (pull_request) Successful in 7m27s Details
/ Tests (1.20) (pull_request) Successful in 5m24s Details
/ Tests (1.21) (pull_request) Successful in 5m0s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-15 11:02:26 +03:00
Denis Kirillov 6788306998 [#328] Log invalid tree service KVs
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-04 15:35:23 +03:00
Denis Kirillov 4ee3648183 [#328] Log invalid lock enabled header
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-04 15:09:51 +03:00
Denis Kirillov ee48d1dc85 [#325] Log error on failed request id generation
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-04 09:49:41 +00:00
Denis Kirillov f958eef2b3 [#325] Use default empty data.LockInfo in get/head in case of error
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-04 09:49:41 +00:00
Denis Kirillov 81b44ab3d3 [#325] Fix mutex usage in controller
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-04 09:49:41 +00:00
Denis Kirillov 623001c403 [#325] Close listener on error
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-04 09:49:41 +00:00
Marina Biryukova 70043c4800 [#324] Close nns resolver after use
Signed-off-by: Marina Biryukova <m.biryukova@yadro.com>
2024-03-04 09:06:26 +00:00
Denis Kirillov 8050ca2d51 [#306] Use session token for container read operations
/ DCO (pull_request) Successful in 1m54s Details
/ Vulncheck (pull_request) Successful in 1m55s Details
/ Builds (1.20) (pull_request) Successful in 2m49s Details
/ Builds (1.21) (pull_request) Successful in 1m56s Details
/ Lint (pull_request) Successful in 3m59s Details
/ Tests (1.20) (pull_request) Successful in 2m30s Details
/ Tests (1.21) (pull_request) Successful in 2m19s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-01 18:14:33 +03:00
Denis Kirillov c12e264697 [#306] Simplify cid resolver for metrics
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-01 17:46:16 +03:00
Denis Kirillov e9f38a49e4 [#306] Fix forming key for bucket cache
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-03-01 16:09:40 +03:00
Denis Kirillov fabb4134bc [#318] Use log msg from constants
/ DCO (pull_request) Successful in 1m44s Details
/ Builds (1.20) (pull_request) Successful in 2m24s Details
/ Builds (1.21) (pull_request) Successful in 2m18s Details
/ Vulncheck (pull_request) Successful in 2m17s Details
/ Lint (pull_request) Successful in 2m36s Details
/ Tests (1.20) (pull_request) Successful in 1m42s Details
/ Tests (1.21) (pull_request) Successful in 1m32s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov e1ee36b979 [#318] Fix tests
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov 937367caaf [#318] Fix panic on invalid multipart form
Previously, simple 'curl -X POST http://localhost:8084/test' leads to panic because of wrong handle matching

Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov 7b86bac6ee [#318] Log unmatched requests
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov 529ec7e0b9 [#318] Don't log empty bucket/name
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov 4741e74210 [#318] Log successfully authenticated accessKeyIDs
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov f1470bab4a [#318] auth: Add context for logged errors
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov 6e5bcaef97 [#318] Log policy request checking
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Denis Kirillov 1522db05c5 [#318] Log namespace for requests
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-29 17:30:28 +03:00
Marina Biryukova 31da31862a [#300] Update error logging in DeleteMultipleObjects
Signed-off-by: Marina Biryukova <m.biryukova@yadro.com>
2024-02-29 14:24:32 +00:00
Denis Kirillov 7de1ffdbe9 [#306] Fix billing tests
/ DCO (pull_request) Successful in 1m43s Details
/ Vulncheck (pull_request) Successful in 1m42s Details
/ Builds (1.20) (pull_request) Successful in 2m34s Details
/ Builds (1.21) (pull_request) Successful in 1m56s Details
/ Lint (pull_request) Successful in 3m50s Details
/ Tests (1.20) (pull_request) Successful in 2m20s Details
/ Tests (1.21) (pull_request) Successful in 2m9s Details
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-28 18:00:27 +03:00
Denis Kirillov 3285a2e105 [#306] policy: Change default access strategy
Use access strategy based on bucket type and/or config flags.

Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-28 17:53:13 +03:00
Denis Kirillov 1bfea006b0 [#306] Update APE
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-28 17:50:08 +03:00
Denis Kirillov 56b50f2075 [#306] Remove flag to disable policy contract
Signed-off-by: Denis Kirillov <d.kirillov@yadro.com>
2024-02-28 17:50:08 +03:00