Uploaded image for project: 'Mesos'
  1. Mesos
  2. MESOS-3903

Add authorization for '/create-volume' and '/destroy-volume' HTTP endpoints

    Details

    • Type: Improvement
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None

      Description

      This is the fourth in a series of tickets that adds authorization support for persistent volumes.

      We need to add ACL authorization for the '/create-volume' and '/destroy-volume' HTTP endpoints. In other complementary work, authorization for frameworks performing CREATE and DESTROY operations is being added by MESOS-3065.

      This will consist of adding authorization calls into the HTTP endpoint code in src/master/http.cpp, as well as tests for both failed & successful calls to '/create-volumes' and '/destroy-volumes' with authorization. We also must ensure that the principal field of Resource.DiskInfo.Persistence is being populated correctly.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                greggomann Greg Mann
                Reporter:
                greggomann Greg Mann
                Shepherd:
                Jie Yu
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: