Differences between `rc` and `mc` for the `anonymous set` command
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 52/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- rust
- 领域
- authorization, cli, security
调研方向
从 rc anonymous set 和 rc anonymous set-json 入口点开始,同时查看有关替换 bucket policy 的警告。比较针对两个前缀依次执行命令所生成的 policy,然后验证现有 statement 保持不变,并确认最终 policy 保留对两个路径的访问权限。
由索引模型根据 Issue 内容生成。
描述
Our team used a workflow similar to this for MinIO mc:
mc alias set local http://localhost:9001 root rootroot
mc mb local/my-bucket
mc anonymous set public "local/my-bucket/persons/music/**"
mc anonymous set public "local/my-bucket/profiles/images/**"
mc anonymous get-json local/my-bucket
Result json policy:
{
"Statement": [
{
"Action": [
"s3:GetBucketLocation",
"s3:ListBucketMultipartUploads"
],
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Resource": [
"arn:aws:s3:::my-bucket"
]
},
{
"Action": [
"s3:ListBucket"
],
"Condition": {
"StringEquals": {
"s3:prefix": [
"persons/music/**",
"profiles/images/**"
]
}
},
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Resource": [
"arn:aws:s3:::my-bucket"
]
},
{
"Action": [
"s3:AbortMultipartUpload",
"s3:DeleteObject",
"s3:GetObject",
"s3:ListMultipartUploadParts",
"s3:PutObject"
],
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Resource": [
"arn:aws:s3:::my-bucket/persons/music/***",
"arn:aws:s3:::my-bucket/profiles/images/***"
]
}
],
"Version": "2012-10-17"
}
After MinIO free Docker images deletion, we decided to switch to RustFS using rc:
rc alias set local http://localhost:9000 root rootroot
rc mb local/my-bucket
rc anonymous set public "local/my-bucket/persons/music"
rc anonymous set public "local/my-bucket/profiles/images"
rc anonymous get-json local/my-bucket
And we get this json policy:
{
"Statement": [
{
"Action": [
"s3:GetObject"
],
"Effect": "Allow",
"Principal": "*",
"Resource": "arn:aws:s3:::my-bucket/profiles/images/*",
"Sid": "AnonymousRead1"
},
{
"Action": "s3:ListBucket",
"Condition": {
"StringLike": {
"s3:prefix": [
"profiles/images",
"profiles/images/*",
"profiles/images*"
]
}
},
"Effect": "Allow",
"Principal": "*",
"Resource": "arn:aws:s3:::my-bucket",
"Sid": "AnonymousList2"
},
{
"Action": [
"s3:PutObject"
],
"Effect": "Allow",
"Principal": "*",
"Resource": "arn:aws:s3:::my-bucket/profiles/images/*",
"Sid": "AnonymousWrite3"
}
],
"Version": "2012-10-17"
}
(Public access to persons/music has been lost)
This slightly disrupted our transition from mc to rc; we had to add a json file and use anonymous set-json command instead.
Is it possible to update the rc so that it extends the existing policy for the bucket rather than overwriting it completely? I noticed there’s a warning message about this when using the cli (Warning: setting 'local/my-bucket/profiles/images' will replace the entire bucket policy for 'my-bucket', which may remove unrelated statements). Is this restriction really necessary?
- 主要语言
- Rust
- 星标
- 159
- 派生
- 23
- 平均合并
- 7 小时 4 分钟
- 30 天内合并 PR
- 10
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
rustfs/cli 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
-
Cannot install and update with brew可能已有人在做 @overtrue 于 2 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 68/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 55/100
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 90/100
chroma-core/chroma#7879 ·
维护者通常 1 天内回复
-
priority middle
难度 1/5 1 小时以内 新手友好度 72/100
KATO-Hiro/AtCoderClans#12838 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 1 天内回复