spcl/serverless-benchmarks

Resource-specific permissions for functions

Open

#215 opened on Jul 27, 2024

View on GitHub
 (0 comments) (0 reactions) (0 assignees)Python (99 forks)auto 404
enhancementgood first issue

Repository metrics

Stars
 (196 stars)
PR merge metrics
 (PR metrics pending)

Description

Right now, our functions are created with permissions to access all needed resources, primarily the object storage buckets and in future key-value storage tables (PR #214)

Instead, we could make SeBS more secure with two additions: allocate permissions only to objects we allocate (e.g. by using prefix sebs-{resource_id} everywhere), and give each function only permissions associated with resources for that specific benchmark.

Contributor guide