Sample: Custom encryption for orchestration state
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- java
- Ambito
- backend-api-design, documentation, security
Direzione di ricerca
Inizia individuando l’interfaccia DataConverter e l’API dello stato di orchestrazione. Chiarisci come devono funzionare la crittografia controllata dall’utente e la rotazione delle chiavi, incluso se le chiavi precedenti rimangono disponibili o se lo stato viene crittografato nuovamente. Il lavoro è completato quando esiste un esempio di riferimento e sono state identificate tutte le modifiche necessarie alla superficie dell’API.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Scenario
There are a variety of users who will need to encrypt their durable state using encryption keys they control. While it's possible to do this directly in the storage layer, it may be beneficial to support this directly in the API layer. The most natural way to do this is to use the DataConverter interface.
One challenge will be with how to deal with key rotation. For example, what happens if an orchestration can run for up to 1 year, but a company has a key rotation policy of 30 days? Do we require that old keys be kept around to decrypt old state, or do we create a mechanism for re-encrypting all orchestration state so that old keys can be fully decommissioned? These are some of the challenges that the sample should try to address.
Besides creating a reference for users to follow, one of the other outcomes could be changes to the API surface.
- Lingua principale
- Java
- Stelle
- 29
- Fork
- 18
- Merge medio
- 1g 10h
- PR unite (30g)
- 2
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoft/durabletask-java
-
Needs: Triage :mag:
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
microsoft/durabletask-java#303 ·
-
Needs: Triage :mag:
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
microsoft/durabletask-java#290 · 2 commenti ·
-
Needs: Triage :mag:
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
microsoft/durabletask-java#285 ·
-
Needs: Triage :mag:
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
microsoft/durabletask-java#276 ·
-
Enhancement
microsoft/durabletask-java#274 · 1 reazione · 2 assegnatari ·
Tutte le issue di microsoft/durabletask-java
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
-
Two open-case totals on one screen: the Programs tile says 15,858 and the nav badge says 15,868 Apertabug frontend maui-pilot
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
objectionary/eo-graphs#74 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100