cockroachdb/cockroach

Explicit auth with TEMP tokens

开放

#56,577 创建于 2020年11月11日

 (6 条评论) (0 个反应) (0 位负责人)Go (4,124 个派生)batch import
C-wishlistT-disaster-recoverygood first issue

仓库指标

星标
 (32,150 个星标)
PR 合并指标
 (平均合并 5天 4小时) (30 天内合并 26 个 PR)

描述

Informs #56536

Use of external storage temp tokens, together with explicit authentication is dangerous. In general, explicitly specified tokens could expire while long running operation (backup, restore) is still executing, without any way for us to regenerate such temp token.

We should error out if external storage URI uses temporary credentials for backup, restore, import, scheduled backup and cdc.

We should also provide an extra URI parameter for the user to specify if they really wish to override this behavior: "&REALLY_USE_TEMP_CREDENTIALS"

Epic CRDB-71

Jira issue: CRDB-2924

贡献者指南