Bug 2273547
Summary: | [rgw-ms][assume-role]:After a successful assume role api call on the secondary site, s3 bucket create fails with http_status 403 | ||
---|---|---|---|
Product: | [Red Hat Storage] Red Hat Ceph Storage | Reporter: | tserlin |
Component: | RGW-Multisite | Assignee: | Matt Benjamin (redhat) <mbenjamin> |
Status: | CLOSED ERRATA | QA Contact: | Vidushi Mishra <vimishra> |
Severity: | high | Docs Contact: | Disha Walvekar <dwalveka> |
Priority: | unspecified | ||
Version: | 6.1 | CC: | ceph-eng-bugs, cephqe-warriors, dwalveka, mbenjamin, mkasturi, prsrivas, smanjara, vereddy, vimishra |
Target Milestone: | --- | Keywords: | Automation |
Target Release: | 7.0z2 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | ceph-18.2.0-180.el9cp | Doc Type: | Bug Fix |
Doc Text: |
Previously, after STS AssumeRole, multisite requests like altering bucket or user metadata that must be forwarded to the primary location were performed without proper credentials at the forwarded location. Due to this bucket creation and other less frequent operations would fail.
With this fix, in case the request is forwarded from a secondary location in a multi-site setup, authenticating the system is done using the system user credentials used to sign the request and permissions are still derived from the role. As a result, multi-site replication now forwards requests authorized by assumed role credentials correctly.
|
Story Points: | --- |
Clone Of: | 2271595 | Environment: | |
Last Closed: | 2024-05-07 12:11:19 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2271399, 2271595, 2293036 | ||
Bug Blocks: | 2270485 |
Description
tserlin
2024-04-05 03:56:59 UTC
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Red Hat Ceph Storage 7.0 Bug Fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2024:2743 The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days |