Uploaded image for project: 'Apache Ozone'
  1. Apache Ozone
  2. HDDS-7814

Implement remote S3 secret storage

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Implemented
    • 1.4.0
    • 1.4.0
    • S3

    Description

      The S3 secrets are currently stored in the RocksDB of the Ozone manager nodes. With this approach, it is not possible to separate the storage of secrets from nodes with an ozone manager. This is a limitation in some environments, for various reasons, such as security issues, so it is proposed to add the ability to store secrets separately from the ozone managers. One of the options for storing secrets would be to use a third-party solution, an example of HashiСorp Vault . Therefore, it is proposed to add the implementation of the storage of S3 secrets based on a remote http server. It is proposed to configure the type of storage using a special property in the ozone site. Leave the current RocksDB as the default implementation to maintain backwards compatibility.

      Attachments

        Issue Links

          Activity

            People

              PochatkinMikhail Mikhail Pochatkin
              PochatkinMikhail Mikhail Pochatkin
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: