From ac97ceb74494f9a5e9f29f3f77847a158cd2101b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=AE=89=E6=AD=A3=E8=B6=85?= Date: Fri, 29 May 2026 19:52:46 +0800 Subject: [PATCH] fix(config): restore default credential startup (#3114) * fix(config): restore default credential startup * fix: align e2e credentials with server env * fix(config): restore default credential consistency --------- Co-authored-by: houseme --- .../docker-compose.cluster.local-build.yml | 16 ++-- .docker/compose/docker-compose.cluster.yaml | 16 ++-- .github/workflows/e2e-s3tests.yml | 4 +- Dockerfile.glibc | 2 + crates/config/src/constants/app.rs | 6 -- crates/targets/src/target/webhook.rs | 75 +++++++++---------- docker-compose.yml | 6 +- entrypoint.sh | 2 +- rustfs/src/config/config_struct.rs | 5 -- rustfs/src/config/config_test.rs | 18 ----- rustfs/src/embedded.rs | 14 +--- rustfs/src/main.rs | 26 ++----- scripts/dev_rustfs.env | 4 +- scripts/e2e-run.sh | 8 +- scripts/run_e2e_tests.sh | 2 +- .../run_four_node_cluster_failover_bench.sh | 4 +- scripts/s3-tests/README.md | 8 +- scripts/s3-tests/run.sh | 10 +-- 18 files changed, 87 insertions(+), 139 deletions(-) diff --git a/.docker/compose/docker-compose.cluster.local-build.yml b/.docker/compose/docker-compose.cluster.local-build.yml index 8f2f5db26..121b5f671 100644 --- a/.docker/compose/docker-compose.cluster.local-build.yml +++ b/.docker/compose/docker-compose.cluster.local-build.yml @@ -23,8 +23,8 @@ services: - RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}} - RUSTFS_ADDRESS=:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin} - - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret} + - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin} + - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin} - RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318} - RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info} - RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false} @@ -55,8 +55,8 @@ services: - RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}} - RUSTFS_ADDRESS=:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin} - - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret} + - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin} + - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin} - RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318} - RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info} - RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false} @@ -87,8 +87,8 @@ services: - RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}} - RUSTFS_ADDRESS=:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin} - - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret} + - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin} + - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin} - RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318} - RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info} - RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false} @@ -119,8 +119,8 @@ services: - RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}} - RUSTFS_ADDRESS=:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin} - - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret} + - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin} + - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin} - RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318} - RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info} - RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false} diff --git a/.docker/compose/docker-compose.cluster.yaml b/.docker/compose/docker-compose.cluster.yaml index 58f381091..0613dee28 100644 --- a/.docker/compose/docker-compose.cluster.yaml +++ b/.docker/compose/docker-compose.cluster.yaml @@ -21,8 +21,8 @@ services: - RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3} - RUSTFS_ADDRESS=0.0.0.0:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=rustfs-cluster-admin - - RUSTFS_SECRET_KEY=rustfs-cluster-secret + - RUSTFS_ACCESS_KEY=rustfsadmin + - RUSTFS_SECRET_KEY=rustfsadmin platform: linux/amd64 ports: - "9000:9000" # Map port 9001 of the host to port 9000 of the container @@ -38,8 +38,8 @@ services: - RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3} - RUSTFS_ADDRESS=0.0.0.0:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=rustfs-cluster-admin - - RUSTFS_SECRET_KEY=rustfs-cluster-secret + - RUSTFS_ACCESS_KEY=rustfsadmin + - RUSTFS_SECRET_KEY=rustfsadmin platform: linux/amd64 ports: - "9001:9000" # Map port 9002 of the host to port 9000 of the container @@ -55,8 +55,8 @@ services: - RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3} - RUSTFS_ADDRESS=0.0.0.0:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=rustfs-cluster-admin - - RUSTFS_SECRET_KEY=rustfs-cluster-secret + - RUSTFS_ACCESS_KEY=rustfsadmin + - RUSTFS_SECRET_KEY=rustfsadmin platform: linux/amd64 ports: - "9002:9000" # Map port 9003 of the host to port 9000 of the container @@ -72,8 +72,8 @@ services: - RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3} - RUSTFS_ADDRESS=0.0.0.0:9000 - RUSTFS_CONSOLE_ENABLE=true - - RUSTFS_ACCESS_KEY=rustfs-cluster-admin - - RUSTFS_SECRET_KEY=rustfs-cluster-secret + - RUSTFS_ACCESS_KEY=rustfsadmin + - RUSTFS_SECRET_KEY=rustfsadmin platform: linux/amd64 ports: - "9003:9000" # Map port 9004 of the host to port 9000 of the container diff --git a/.github/workflows/e2e-s3tests.yml b/.github/workflows/e2e-s3tests.yml index 06b696abc..a2a8829ae 100644 --- a/.github/workflows/e2e-s3tests.yml +++ b/.github/workflows/e2e-s3tests.yml @@ -40,8 +40,8 @@ on: env: # main user - S3_ACCESS_KEY: rustfs-ci-admin - S3_SECRET_KEY: rustfs-ci-secret + S3_ACCESS_KEY: rustfsadmin + S3_SECRET_KEY: rustfsadmin # alt user (must be different from main for many s3-tests) S3_ALT_ACCESS_KEY: rustfsalt S3_ALT_SECRET_KEY: rustfsalt diff --git a/Dockerfile.glibc b/Dockerfile.glibc index 20005d983..4ca9e40e7 100644 --- a/Dockerfile.glibc +++ b/Dockerfile.glibc @@ -105,6 +105,8 @@ RUN groupadd -g 10001 rustfs && \ ENV RUSTFS_ADDRESS=":9000" \ RUSTFS_CONSOLE_ADDRESS=":9001" \ + RUSTFS_ACCESS_KEY="rustfsadmin" \ + RUSTFS_SECRET_KEY="rustfsadmin" \ RUSTFS_CONSOLE_ENABLE="true" \ RUSTFS_CONSOLE_CORS_ALLOWED_ORIGINS="*" \ RUSTFS_VOLUMES="/data" \ diff --git a/crates/config/src/constants/app.rs b/crates/config/src/constants/app.rs index 766146a45..20932fc50 100644 --- a/crates/config/src/constants/app.rs +++ b/crates/config/src/constants/app.rs @@ -155,12 +155,6 @@ pub const ENV_RUSTFS_SECRET_KEY: &str = "RUSTFS_SECRET_KEY"; /// Environment variable for server secret key file. pub const ENV_RUSTFS_SECRET_KEY_FILE: &str = "RUSTFS_SECRET_KEY_FILE"; -/// Environment variable to explicitly allow public default root credentials. -/// -/// This is intended for local development only. Production startup paths should -/// provide non-default `RUSTFS_ACCESS_KEY` and `RUSTFS_SECRET_KEY` values. -pub const ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS: &str = "RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS"; - /// Environment variable controlling startup behavior when unsupported filesystem types are detected. /// /// Accepted values: diff --git a/crates/targets/src/target/webhook.rs b/crates/targets/src/target/webhook.rs index 5c65cdccd..c1ead7555 100644 --- a/crates/targets/src/target/webhook.rs +++ b/crates/targets/src/target/webhook.rs @@ -192,6 +192,10 @@ where let mut client_builder = Client::builder() .timeout(Duration::from_secs(30)) .user_agent(crate::get_user_agent(crate::ServiceType::Basis)); + #[cfg(test)] + { + client_builder = client_builder.no_proxy(); + } // 1. Configure server certificate verification if args.skip_tls_verify { @@ -560,7 +564,6 @@ mod tests { use super::{WebhookArgs, WebhookTarget}; use crate::target::{Target, TargetType, decode_object_name}; use tokio::net::TcpListener; - use tokio::sync::mpsc; use url::Url; use url::form_urlencoded; @@ -679,43 +682,37 @@ mod tests { async fn test_is_active_uses_origin_reachability_for_path_endpoints() { let listener = TcpListener::bind("127.0.0.1:0").await.unwrap(); let address = listener.local_addr().unwrap(); - let (path_tx, mut path_rx) = mpsc::channel(1); - let accept_task = tokio::spawn(async move { + let server = async move { + use tokio::io::{AsyncReadExt, AsyncWriteExt}; + + let (mut stream, _) = listener.accept().await.unwrap(); + let mut request = Vec::new(); + let mut buf = [0u8; 1024]; loop { - let (mut stream, _) = listener.accept().await.unwrap(); - let path_tx = path_tx.clone(); - tokio::spawn(async move { - use tokio::io::{AsyncReadExt, AsyncWriteExt}; - - let mut request = Vec::new(); - let mut buf = [0u8; 1024]; - loop { - let read = stream.read(&mut buf).await.unwrap(); - if read == 0 { - break; - } - request.extend_from_slice(&buf[..read]); - if request.windows(4).any(|window| window == b"\r\n\r\n") { - break; - } - } - - let request_line = request - .split(|byte| *byte == b'\n') - .next() - .and_then(|line| std::str::from_utf8(line).ok()) - .unwrap_or_default() - .trim(); - let path = request_line.split_whitespace().nth(1).unwrap_or_default().to_string(); - let _ = path_tx.send(path.clone()).await; - - if path == "/" { - let response = b"HTTP/1.1 200 OK\r\nContent-Length: 0\r\nConnection: close\r\n\r\n"; - let _ = stream.write_all(response).await; - } - }); + let read = stream.read(&mut buf).await.unwrap(); + if read == 0 { + break; + } + request.extend_from_slice(&buf[..read]); + if request.windows(4).any(|window| window == b"\r\n\r\n") { + break; + } } - }); + + let request_line = request + .split(|byte| *byte == b'\n') + .next() + .and_then(|line| std::str::from_utf8(line).ok()) + .unwrap_or_default() + .trim(); + let path = request_line.split_whitespace().nth(1).unwrap_or_default().to_string(); + + if path == "/" { + let response = b"HTTP/1.1 200 OK\r\nContent-Length: 0\r\nConnection: close\r\n\r\n"; + let _ = stream.write_all(response).await; + } + path + }; let args = WebhookArgs { endpoint: Url::parse(&format!("http://{address}/hook")).unwrap(), @@ -723,8 +720,8 @@ mod tests { }; let target = WebhookTarget::::new("path-probe".to_string(), args).unwrap(); - assert!(target.is_active().await.unwrap()); - assert_eq!(path_rx.recv().await.unwrap(), "/"); - accept_task.abort(); + let (is_active, path) = tokio::join!(target.is_active(), server); + assert!(is_active.unwrap()); + assert_eq!(path, "/"); } } diff --git a/docker-compose.yml b/docker-compose.yml index 13824f967..f63a90e07 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -33,8 +33,10 @@ services: - RUSTFS_CONSOLE_ADDRESS=0.0.0.0:9001 - RUSTFS_CONSOLE_ENABLE=true - RUSTFS_CONSOLE_CORS_ALLOWED_ORIGINS=* - - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:?Set RUSTFS_ACCESS_KEY to a non-default value} - - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:?Set RUSTFS_SECRET_KEY to a non-default value} + # SECURITY: these defaults are public and well-known. + # Override via env vars before exposing the listener beyond localhost. + - RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin} + - RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin} - RUSTFS_OBS_LOGGER_LEVEL=info - RUSTFS_TLS_PATH=/opt/tls - RUSTFS_OBS_ENDPOINT=http://otel-collector:4318 diff --git a/entrypoint.sh b/entrypoint.sh index 252abff61..49364facb 100755 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -114,7 +114,7 @@ process_log_directory # 4) Default credentials warning if [ "${RUSTFS_ACCESS_KEY:-}" = "rustfsadmin" ] || [ "${RUSTFS_SECRET_KEY:-}" = "rustfsadmin" ]; then - echo "!!!WARNING: Default credentials are only allowed on loopback or with explicit insecure local-dev opt-in." + echo "!!!WARNING: Using default RUSTFS_ACCESS_KEY or RUSTFS_SECRET_KEY. Override them in production!" fi # 5) Append DATA_VOLUMES only if no data paths in arguments diff --git a/rustfs/src/config/config_struct.rs b/rustfs/src/config/config_struct.rs index 6c6f238a7..1d6dc1e7e 100644 --- a/rustfs/src/config/config_struct.rs +++ b/rustfs/src/config/config_struct.rs @@ -24,7 +24,6 @@ use rustfs_config::{ }; use rustfs_credentials::{DEFAULT_ACCESS_KEY, DEFAULT_SECRET_KEY, Masked}; use std::collections::HashSet; -use std::net::SocketAddr; use std::sync::{Mutex, OnceLock}; pub(crate) const LEGACY_ENV_RUSTFS_ROOT_USER: &str = "RUSTFS_ROOT_USER"; @@ -179,10 +178,6 @@ impl Config { DEFAULT_ACCESS_KEY.eq(&self.access_key) && DEFAULT_SECRET_KEY.eq(&self.secret_key) } - pub fn default_credentials_allowed_for_addr(&self, server_addr: SocketAddr, allow_insecure_defaults: bool) -> bool { - !self.is_using_default_credentials() || server_addr.ip().is_loopback() || allow_insecure_defaults - } - /// Create Config from Opt pub(super) fn from_opt(opt: Opt) -> std::io::Result { let Opt { diff --git a/rustfs/src/config/config_test.rs b/rustfs/src/config/config_test.rs index 714af70c7..57655f554 100644 --- a/rustfs/src/config/config_test.rs +++ b/rustfs/src/config/config_test.rs @@ -141,24 +141,6 @@ mod tests { assert_eq!(config.buffer_profile, "GeneralPurpose"); } - #[test] - fn default_credentials_allowed_only_for_loopback_or_explicit_opt_in() { - let config = Config::new("0.0.0.0:9000", vec!["/tmp/rustfs-vol1".to_string()]); - - assert!(!config.default_credentials_allowed_for_addr("0.0.0.0:9000".parse().unwrap(), false)); - assert!(config.default_credentials_allowed_for_addr("127.0.0.1:9000".parse().unwrap(), false)); - assert!(config.default_credentials_allowed_for_addr("0.0.0.0:9000".parse().unwrap(), true)); - } - - #[test] - fn custom_credentials_allowed_on_non_loopback() { - let mut config = Config::new("0.0.0.0:9000", vec!["/tmp/rustfs-vol1".to_string()]); - config.access_key = "custom-access-key".to_string(); - config.secret_key = "custom-secret-key".to_string(); - - assert!(config.default_credentials_allowed_for_addr("0.0.0.0:9000".parse().unwrap(), false)); - } - #[test] #[serial] fn test_custom_console_configuration() { diff --git a/rustfs/src/embedded.rs b/rustfs/src/embedded.rs index 6f047cdee..494759fb3 100644 --- a/rustfs/src/embedded.rs +++ b/rustfs/src/embedded.rs @@ -55,7 +55,6 @@ use crate::server::{ }; use crate::startup_fs_guard::enforce_unsupported_fs_policy; use rustfs_common::{GlobalReadiness, SystemStage, set_global_addr}; -use rustfs_config::ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS; use rustfs_credentials::init_global_action_credentials; use rustfs_ecstore::store::init_lock_clients; use rustfs_ecstore::{ @@ -77,7 +76,7 @@ use rustfs_ecstore::{ }; use rustfs_iam::init_iam_sys; use rustfs_obs::{init_obs, set_global_guard}; -use rustfs_utils::{get_env_bool, net::parse_and_resolve_address}; +use rustfs_utils::net::parse_and_resolve_address; use rustls::crypto::aws_lc_rs::default_provider; use std::net::{IpAddr, Ipv4Addr, Ipv6Addr, SocketAddr}; use std::path::{Path, PathBuf}; @@ -308,8 +307,7 @@ impl RustFSServerBuilder { // Trusted proxies. rustfs_trusted_proxies::init(); - // Resolve listen address before credential initialization so unsafe - // default credentials can fail before the server binds a listener. + // Resolve listen address before endpoint/global initialization. let server_addr = parse_and_resolve_address(config.address.as_str()).map_err(|e| ServerError::Init(format!("address: {e}")))?; @@ -322,14 +320,6 @@ impl RustFSServerBuilder { )); } - let allow_insecure_defaults = get_env_bool(ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS, false); - if !config.default_credentials_allowed_for_addr(server_addr, allow_insecure_defaults) { - return Err(ServerError::Init( - "default root credentials are not allowed on non-loopback listeners; set access_key and secret_key to non-default values, bind to loopback, or set RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS=true for local development only" - .to_string(), - )); - } - // Credentials. init_global_action_credentials(Some(config.access_key.clone()), Some(config.secret_key.clone())) .map_err(|e| ServerError::Init(format!("credentials: {e:?}")))?; diff --git a/rustfs/src/main.rs b/rustfs/src/main.rs index deccc5af1..7b43b46c5 100644 --- a/rustfs/src/main.rs +++ b/rustfs/src/main.rs @@ -36,7 +36,6 @@ use rustfs::server::{ }; use rustfs::startup_fs_guard::enforce_unsupported_fs_policy; use rustfs_common::{GlobalReadiness, SystemStage, set_global_addr}; -use rustfs_config::ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS; use rustfs_credentials::init_global_action_credentials; use rustfs_ecstore::store::init_lock_clients; use rustfs_ecstore::{ @@ -62,7 +61,7 @@ use rustfs_iam::{init_iam_sys, init_oidc_sys}; use rustfs_obs::{init_metrics_runtime, init_obs, set_global_guard}; use rustfs_scanner::init_data_scanner; use rustfs_utils::{ - ExternalEnvCompatReport, apply_external_env_compat, get_env_bool, get_env_bool_with_aliases, net::parse_and_resolve_address, + ExternalEnvCompatReport, apply_external_env_compat, get_env_bool_with_aliases, net::parse_and_resolve_address, }; use rustls::crypto::aws_lc_rs::default_provider; use std::io::{Error, Result}; @@ -135,12 +134,7 @@ fn is_using_default_credentials(config: &rustfs::config::Config) -> bool { config.is_using_default_credentials() } -const DEFAULT_CREDENTIALS_WARNING_MESSAGE: &str = "Detected default root credentials; set RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY to non-default values, or use RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS=true only for local development"; -const DEFAULT_CREDENTIALS_ERROR_MESSAGE: &str = "Default root credentials are not allowed on non-loopback listeners; set RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY to non-default values, bind to loopback, or set RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS=true for local development only"; - -fn allow_insecure_default_credentials() -> bool { - get_env_bool(ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS, false) -} +const DEFAULT_CREDENTIALS_WARNING_MESSAGE: &str = "Detected default root credentials; set RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY to non-default values for production deployments"; async fn async_main() -> Result<()> { // Parse command line arguments @@ -275,11 +269,6 @@ async fn run(config: rustfs::config::Config) -> Result<()> { let server_port = server_addr.port(); let server_address = server_addr.to_string(); - if !config.default_credentials_allowed_for_addr(server_addr, allow_insecure_default_credentials()) { - error!("{DEFAULT_CREDENTIALS_ERROR_MESSAGE}"); - return Err(Error::other(DEFAULT_CREDENTIALS_ERROR_MESSAGE)); - } - if is_using_default_credentials(&config) { warn!("{}", DEFAULT_CREDENTIALS_WARNING_MESSAGE); } @@ -826,12 +815,9 @@ mod tests { #[test] fn default_credentials_messages_are_actionable_without_exposing_values() { - for message in [DEFAULT_CREDENTIALS_WARNING_MESSAGE, DEFAULT_CREDENTIALS_ERROR_MESSAGE] { - assert!(message.contains(rustfs_config::ENV_RUSTFS_ACCESS_KEY)); - assert!(message.contains(rustfs_config::ENV_RUSTFS_SECRET_KEY)); - assert!(message.contains(ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS)); - assert!(!message.contains(rustfs_credentials::DEFAULT_ACCESS_KEY)); - assert!(!message.contains(rustfs_credentials::DEFAULT_SECRET_KEY)); - } + assert!(DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_config::ENV_RUSTFS_ACCESS_KEY)); + assert!(DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_config::ENV_RUSTFS_SECRET_KEY)); + assert!(!DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_credentials::DEFAULT_ACCESS_KEY)); + assert!(!DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_credentials::DEFAULT_SECRET_KEY)); } } diff --git a/scripts/dev_rustfs.env b/scripts/dev_rustfs.env index 8debedfaa..c9754b506 100644 --- a/scripts/dev_rustfs.env +++ b/scripts/dev_rustfs.env @@ -1,5 +1,5 @@ -RUSTFS_ACCESS_KEY=rustfs-dev-admin -RUSTFS_SECRET_KEY=rustfs-dev-secret +RUSTFS_ACCESS_KEY=rustfsadmin +RUSTFS_SECRET_KEY=rustfsadmin RUSTFS_VOLUMES="http://node{1...4}:7000/data/rustfs{0...3} http://node{5...8}:7000/data/rustfs{0...3}" RUSTFS_ADDRESS=":7000" diff --git a/scripts/e2e-run.sh b/scripts/e2e-run.sh index 8413b2fa1..632f89412 100755 --- a/scripts/e2e-run.sh +++ b/scripts/e2e-run.sh @@ -20,16 +20,16 @@ VOLUME=$2 chmod +x $BIN mkdir -p $VOLUME +export RUSTFS_ACCESS_KEY="${RUSTFS_ACCESS_KEY:-rustfsadmin}" +export RUSTFS_SECRET_KEY="${RUSTFS_SECRET_KEY:-rustfsadmin}" export RUST_LOG="rustfs=debug,ecstore=debug,s3s=debug,iam=debug" export RUST_BACKTRACE=full -export RUSTFS_ACCESS_KEY=rustfs-e2e-admin -export RUSTFS_SECRET_KEY=rustfs-e2e-secret $BIN $VOLUME > /tmp/rustfs.log 2>&1 & sleep 10 -export AWS_ACCESS_KEY_ID=$RUSTFS_ACCESS_KEY -export AWS_SECRET_ACCESS_KEY=$RUSTFS_SECRET_KEY +export AWS_ACCESS_KEY_ID="${RUSTFS_ACCESS_KEY:-rustfsadmin}" +export AWS_SECRET_ACCESS_KEY="${RUSTFS_SECRET_KEY:-rustfsadmin}" export AWS_REGION=us-east-1 export AWS_ENDPOINT_URL=http://localhost:9000 export RUST_LOG="s3s_e2e=debug,s3s_test=info,s3s=debug" diff --git a/scripts/run_e2e_tests.sh b/scripts/run_e2e_tests.sh index 5a10a6490..810aec5fd 100755 --- a/scripts/run_e2e_tests.sh +++ b/scripts/run_e2e_tests.sh @@ -134,7 +134,7 @@ start_rustfs() { # Start RustFS in background with environment variables cd "$TARGET_DIR" - RUSTFS_ACCESS_KEY=rustfs-e2e-admin RUSTFS_SECRET_KEY=rustfs-e2e-secret \ + RUSTFS_ACCESS_KEY=rustfsadmin RUSTFS_SECRET_KEY=rustfsadmin \ RUSTFS_OBS_LOG_DIRECTORY="$TARGET_DIR/logs" \ ./rustfs --address :9000 "$DATA_DIR" > rustfs.log 2>&1 & RUSTFS_PID=$! diff --git a/scripts/run_four_node_cluster_failover_bench.sh b/scripts/run_four_node_cluster_failover_bench.sh index 4b5303249..34f7c4036 100755 --- a/scripts/run_four_node_cluster_failover_bench.sh +++ b/scripts/run_four_node_cluster_failover_bench.sh @@ -15,8 +15,8 @@ PRECHECK_AUTO_CLEANUP="${PRECHECK_AUTO_CLEANUP:-true}" WAIT_PROBE_MODE="${WAIT_PROBE_MODE:-service}" COMPOSE_UP_NO_BUILD="${COMPOSE_UP_NO_BUILD:-false}" -RUSTFS_ACCESS_KEY="${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin}" -RUSTFS_SECRET_KEY="${RUSTFS_SECRET_KEY:-rustfs-cluster-secret}" +RUSTFS_ACCESS_KEY="${RUSTFS_ACCESS_KEY:-rustfsadmin}" +RUSTFS_SECRET_KEY="${RUSTFS_SECRET_KEY:-rustfsadmin}" RUSTFS_DOCKER_PLATFORM="${RUSTFS_DOCKER_PLATFORM:-}" RUSTFS_OBS_ENDPOINT="${RUSTFS_OBS_ENDPOINT:-}" RUSTFS_UNSAFE_BYPASS_DISK_CHECK="${RUSTFS_UNSAFE_BYPASS_DISK_CHECK:-true}" diff --git a/scripts/s3-tests/README.md b/scripts/s3-tests/README.md index df484f8dc..b6a7683fe 100644 --- a/scripts/s3-tests/README.md +++ b/scripts/s3-tests/README.md @@ -130,8 +130,8 @@ DEPLOY_MODE=existing S3_HOST=192.168.1.100 S3_PORT=9000 ./scripts/s3-tests/run.s ### Service Configuration -- `S3_ACCESS_KEY`: Main user access key (default: `rustfs-ci-admin`) -- `S3_SECRET_KEY`: Main user secret key (default: `rustfs-ci-secret`) +- `S3_ACCESS_KEY`: Main user access key (default: `rustfsadmin`) +- `S3_SECRET_KEY`: Main user secret key (default: `rustfsadmin`) - `S3_ALT_ACCESS_KEY`: Alt user access key (default: `rustfsalt`) - `S3_ALT_SECRET_KEY`: Alt user secret key (default: `rustfsalt`) - `S3_REGION`: S3 region (default: `us-east-1`) @@ -420,8 +420,8 @@ curl http://192.168.1.100:9000/health # Verify S3 API is responding awscurl --service s3 --region us-east-1 \ - --access_key rustfs-ci-admin \ - --secret_key rustfs-ci-secret \ + --access_key rustfsadmin \ + --secret_key rustfsadmin \ -X GET "http://192.168.1.100:9000/" ``` diff --git a/scripts/s3-tests/run.sh b/scripts/s3-tests/run.sh index 3eb91aec9..fd19bd9a3 100755 --- a/scripts/s3-tests/run.sh +++ b/scripts/s3-tests/run.sh @@ -25,8 +25,8 @@ PYTHON_VERSION=$(python3 -c "import sys; print(f'{sys.version_info.major}.{sys.v export PATH="$HOME/Library/Python/${PYTHON_VERSION}/bin:$HOME/.local/bin:$PATH" # Configuration -S3_ACCESS_KEY="${S3_ACCESS_KEY:-rustfs-ci-admin}" -S3_SECRET_KEY="${S3_SECRET_KEY:-rustfs-ci-secret}" +S3_ACCESS_KEY="${S3_ACCESS_KEY:-rustfsadmin}" +S3_SECRET_KEY="${S3_SECRET_KEY:-rustfsadmin}" S3_ALT_ACCESS_KEY="${S3_ALT_ACCESS_KEY:-rustfsalt}" S3_ALT_SECRET_KEY="${S3_ALT_SECRET_KEY:-rustfsalt}" S3_REGION="${S3_REGION:-us-east-1}" @@ -218,8 +218,8 @@ Environment Variables: RUSTFS_BINARY - Path to RustFS binary (for binary mode, default: ./target/release/rustfs) S3_HOST - S3 service host (default: 127.0.0.1) S3_PORT - S3 service port (default: 9000) - S3_ACCESS_KEY - Main user access key (default: rustfs-ci-admin) - S3_SECRET_KEY - Main user secret key (default: rustfs-ci-secret) + S3_ACCESS_KEY - Main user access key (default: rustfsadmin) + S3_SECRET_KEY - Main user secret key (default: rustfsadmin) S3_ALT_ACCESS_KEY - Alt user access key (default: rustfsalt) S3_ALT_SECRET_KEY - Alt user secret key (default: rustfsalt) MAXFAIL - Stop after N failures (default: 1) @@ -690,7 +690,7 @@ envsubst < "${TEMPLATE_PATH}" > "${CONF_OUTPUT_PATH}" || { } # Step 7: Provision s3-tests alt user -# Note: The configured main user is a system user and doesn't need to be created via API +# Note: Main user (rustfsadmin) is a system user and doesn't need to be created via API log_info "Provisioning s3-tests alt user..." # Helper function to install Python packages with fallback for externally-managed environments