cockroachdb/cockroach

Explicit auth with TEMP tokens

Offen

#56.577 geöffnet am 11.11.2020

 (6 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)Go (4.124 Forks)batch import
C-wishlistT-disaster-recoverygood first issue

Repository-Metriken

Stars
 (32.150 Sterne)
PR-Merge-Metriken
 (Durchschn. Merge 5T 4h) (26 gemergte PRs in 30 T)

Beschreibung

Informs #56536

Use of external storage temp tokens, together with explicit authentication is dangerous. In general, explicitly specified tokens could expire while long running operation (backup, restore) is still executing, without any way for us to regenerate such temp token.

We should error out if external storage URI uses temporary credentials for backup, restore, import, scheduled backup and cdc.

We should also provide an extra URI parameter for the user to specify if they really wish to override this behavior: "&REALLY_USE_TEMP_CREDENTIALS"

Epic CRDB-71

Jira issue: CRDB-2924

Contributor Guide