Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Differences between `rc` and `mc` for the `anonymous set` command

未关闭
#378 0 条评论 3 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
52/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
活跃
技术栈
rust

调研方向

从 rc anonymous set 和 rc anonymous set-json 入口点开始,同时查看有关替换 bucket policy 的警告。比较针对两个前缀依次执行命令所生成的 policy,然后验证现有 statement 保持不变,并确认最终 policy 保留对两个路径的访问权限。

由索引模型根据 Issue 内容生成。

描述

Our team used a workflow similar to this for MinIO mc:

mc alias set local http://localhost:9001 root rootroot
mc mb local/my-bucket
mc anonymous set public "local/my-bucket/persons/music/**"
mc anonymous set public "local/my-bucket/profiles/images/**"
mc anonymous get-json local/my-bucket

Result json policy:

{
 "Statement": [
  {
   "Action": [
    "s3:GetBucketLocation",
    "s3:ListBucketMultipartUploads"
   ],
   "Effect": "Allow",
   "Principal": {
    "AWS": [
     "*"
    ]
   },
   "Resource": [
    "arn:aws:s3:::my-bucket"
   ]
  },
  {
   "Action": [
    "s3:ListBucket"
   ],
   "Condition": {
    "StringEquals": {
     "s3:prefix": [
      "persons/music/**",
      "profiles/images/**"
     ]
    }
   },
   "Effect": "Allow",
   "Principal": {
    "AWS": [
     "*"
    ]
   },
   "Resource": [
    "arn:aws:s3:::my-bucket"
   ]
  },
  {
   "Action": [
    "s3:AbortMultipartUpload",
    "s3:DeleteObject",
    "s3:GetObject",
    "s3:ListMultipartUploadParts",
    "s3:PutObject"
   ],
   "Effect": "Allow",
   "Principal": {
    "AWS": [
     "*"
    ]
   },
   "Resource": [
    "arn:aws:s3:::my-bucket/persons/music/***",
    "arn:aws:s3:::my-bucket/profiles/images/***"
   ]
  }
 ],
 "Version": "2012-10-17"
}

After MinIO free Docker images deletion, we decided to switch to RustFS using rc:

rc alias set local http://localhost:9000 root rootroot
rc mb local/my-bucket
rc anonymous set public "local/my-bucket/persons/music"
rc anonymous set public "local/my-bucket/profiles/images"
rc anonymous get-json local/my-bucket

And we get this json policy:

{
  "Statement": [
    {
      "Action": [
        "s3:GetObject"
      ],
      "Effect": "Allow",
      "Principal": "*",
      "Resource": "arn:aws:s3:::my-bucket/profiles/images/*",
      "Sid": "AnonymousRead1"
    },
    {
      "Action": "s3:ListBucket",
      "Condition": {
        "StringLike": {
          "s3:prefix": [
            "profiles/images",
            "profiles/images/*",
            "profiles/images*"
          ]
        }
      },
      "Effect": "Allow",
      "Principal": "*",
      "Resource": "arn:aws:s3:::my-bucket",
      "Sid": "AnonymousList2"
    },
    {
      "Action": [
        "s3:PutObject"
      ],
      "Effect": "Allow",
      "Principal": "*",
      "Resource": "arn:aws:s3:::my-bucket/profiles/images/*",
      "Sid": "AnonymousWrite3"
    }
  ],
  "Version": "2012-10-17"
}

(Public access to persons/music has been lost)

This slightly disrupted our transition from mc to rc; we had to add a json file and use anonymous set-json command instead.

Is it possible to update the rc so that it extends the existing policy for the bucket rather than overwriting it completely? I noticed there’s a warning message about this when using the cli (Warning: setting 'local/my-bucket/profiles/images' will replace the entire bucket policy for 'my-bucket', which may remove unrelated statements). Is this restriction really necessary?

主要语言
Rust
星标
159
派生
23
平均合并
7 小时 4 分钟
30 天内合并 PR
10

环境准备

  • 提供 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 没有贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

rustfs/cli 的其他 Issue

查看 rustfs/cli 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。