spcl/serverless-benchmarks
Resource-specific permissions for functions
Offen
#215 geöffnet am 27.07.2024
enhancementgood first issue
Repository-Metriken
- Stars
- (196 Sterne)
- PR-Merge-Metriken
- (PR-Metriken ausstehend)
Beschreibung
Right now, our functions are created with permissions to access all needed resources, primarily the object storage buckets and in future key-value storage tables (PR #214)
Instead, we could make SeBS more secure with two additions: allocate permissions only to objects we allocate (e.g. by using prefix sebs-{resource_id} everywhere), and give each function only permissions associated with resources for that specific benchmark.