generated from TrueCloudLab/basic
Ignore local overrides with Allow
status in chain router #97
No reviewers
TrueCloudLab/storage-services-developers
TrueCloudLab/storage-services-committers
Labels
No labels
Infrastructure
blocked
bug
config
discussion
documentation
duplicate
enhancement
go
help wanted
internal
invalid
kludge
observability
perfomance
question
refactoring
wontfix
No milestone
No project
No assignees
4 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: TrueCloudLab/policy-engine#97
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "aarifullin/policy-engine:fix/83_ignore_override_allow"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
TestInmemory_MultipleTargets
;TestLocalOverrideAllowRule
.Close #83
Allow
statusThe whole point of local overrides is to allow doing anything intentionally.
Why is this a problem?
@fyrchik wrote in #97 (comment):
The dilemma is quite sensitive for public networks:
allow object.* *
for root namespace !allow object.* *
for root namespace !At the same time:
A container owner conceived to permit the access to sensitive data only for couple of public key.
If some objects are reported for some kind of abuse, nodes are able to easily set denying overrides for object or whole container.
Perhaps, a frostfs-storage's owner should be able to allow the access for a particular user (e.g. investigation), but I am concerned about 1), 2). That might be a disaster.
Everything else can be solved by a node owner as he's got a wallet that identified as the role
container
.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.