mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-26 08:18:18 +00:00
fix(config): restore default credential startup (#3114)
* fix(config): restore default credential startup * fix: align e2e credentials with server env * fix(config): restore default credential consistency --------- Co-authored-by: houseme <housemecn@gmail.com>
This commit is contained in:
@@ -23,8 +23,8 @@ services:
|
||||
- RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}}
|
||||
- RUSTFS_ADDRESS=:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret}
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin}
|
||||
- RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318}
|
||||
- RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info}
|
||||
- RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false}
|
||||
@@ -55,8 +55,8 @@ services:
|
||||
- RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}}
|
||||
- RUSTFS_ADDRESS=:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret}
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin}
|
||||
- RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318}
|
||||
- RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info}
|
||||
- RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false}
|
||||
@@ -87,8 +87,8 @@ services:
|
||||
- RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}}
|
||||
- RUSTFS_ADDRESS=:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret}
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin}
|
||||
- RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318}
|
||||
- RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info}
|
||||
- RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false}
|
||||
@@ -119,8 +119,8 @@ services:
|
||||
- RUSTFS_VOLUMES=${RUSTFS_VOLUMES:-http://node{1...4}:9000/data/rustfs{0...3}}
|
||||
- RUSTFS_ADDRESS=:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfs-cluster-secret}
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin}
|
||||
- RUSTFS_OBS_ENDPOINT=${RUSTFS_OBS_ENDPOINT:-http://host.docker.internal:4318}
|
||||
- RUSTFS_OBS_LOGGER_LEVEL=${RUSTFS_OBS_LOGGER_LEVEL:-info}
|
||||
- RUSTFS_OBS_USE_STDOUT=${RUSTFS_OBS_USE_STDOUT:-false}
|
||||
|
||||
@@ -21,8 +21,8 @@ services:
|
||||
- RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3}
|
||||
- RUSTFS_ADDRESS=0.0.0.0:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=rustfs-cluster-admin
|
||||
- RUSTFS_SECRET_KEY=rustfs-cluster-secret
|
||||
- RUSTFS_ACCESS_KEY=rustfsadmin
|
||||
- RUSTFS_SECRET_KEY=rustfsadmin
|
||||
platform: linux/amd64
|
||||
ports:
|
||||
- "9000:9000" # Map port 9001 of the host to port 9000 of the container
|
||||
@@ -38,8 +38,8 @@ services:
|
||||
- RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3}
|
||||
- RUSTFS_ADDRESS=0.0.0.0:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=rustfs-cluster-admin
|
||||
- RUSTFS_SECRET_KEY=rustfs-cluster-secret
|
||||
- RUSTFS_ACCESS_KEY=rustfsadmin
|
||||
- RUSTFS_SECRET_KEY=rustfsadmin
|
||||
platform: linux/amd64
|
||||
ports:
|
||||
- "9001:9000" # Map port 9002 of the host to port 9000 of the container
|
||||
@@ -55,8 +55,8 @@ services:
|
||||
- RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3}
|
||||
- RUSTFS_ADDRESS=0.0.0.0:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=rustfs-cluster-admin
|
||||
- RUSTFS_SECRET_KEY=rustfs-cluster-secret
|
||||
- RUSTFS_ACCESS_KEY=rustfsadmin
|
||||
- RUSTFS_SECRET_KEY=rustfsadmin
|
||||
platform: linux/amd64
|
||||
ports:
|
||||
- "9002:9000" # Map port 9003 of the host to port 9000 of the container
|
||||
@@ -72,8 +72,8 @@ services:
|
||||
- RUSTFS_VOLUMES=http://node{0...3}:9000/data/rustfs{0...3}
|
||||
- RUSTFS_ADDRESS=0.0.0.0:9000
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_ACCESS_KEY=rustfs-cluster-admin
|
||||
- RUSTFS_SECRET_KEY=rustfs-cluster-secret
|
||||
- RUSTFS_ACCESS_KEY=rustfsadmin
|
||||
- RUSTFS_SECRET_KEY=rustfsadmin
|
||||
platform: linux/amd64
|
||||
ports:
|
||||
- "9003:9000" # Map port 9004 of the host to port 9000 of the container
|
||||
|
||||
@@ -40,8 +40,8 @@ on:
|
||||
|
||||
env:
|
||||
# main user
|
||||
S3_ACCESS_KEY: rustfs-ci-admin
|
||||
S3_SECRET_KEY: rustfs-ci-secret
|
||||
S3_ACCESS_KEY: rustfsadmin
|
||||
S3_SECRET_KEY: rustfsadmin
|
||||
# alt user (must be different from main for many s3-tests)
|
||||
S3_ALT_ACCESS_KEY: rustfsalt
|
||||
S3_ALT_SECRET_KEY: rustfsalt
|
||||
|
||||
@@ -105,6 +105,8 @@ RUN groupadd -g 10001 rustfs && \
|
||||
|
||||
ENV RUSTFS_ADDRESS=":9000" \
|
||||
RUSTFS_CONSOLE_ADDRESS=":9001" \
|
||||
RUSTFS_ACCESS_KEY="rustfsadmin" \
|
||||
RUSTFS_SECRET_KEY="rustfsadmin" \
|
||||
RUSTFS_CONSOLE_ENABLE="true" \
|
||||
RUSTFS_CONSOLE_CORS_ALLOWED_ORIGINS="*" \
|
||||
RUSTFS_VOLUMES="/data" \
|
||||
|
||||
@@ -155,12 +155,6 @@ pub const ENV_RUSTFS_SECRET_KEY: &str = "RUSTFS_SECRET_KEY";
|
||||
/// Environment variable for server secret key file.
|
||||
pub const ENV_RUSTFS_SECRET_KEY_FILE: &str = "RUSTFS_SECRET_KEY_FILE";
|
||||
|
||||
/// Environment variable to explicitly allow public default root credentials.
|
||||
///
|
||||
/// This is intended for local development only. Production startup paths should
|
||||
/// provide non-default `RUSTFS_ACCESS_KEY` and `RUSTFS_SECRET_KEY` values.
|
||||
pub const ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS: &str = "RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS";
|
||||
|
||||
/// Environment variable controlling startup behavior when unsupported filesystem types are detected.
|
||||
///
|
||||
/// Accepted values:
|
||||
|
||||
@@ -192,6 +192,10 @@ where
|
||||
let mut client_builder = Client::builder()
|
||||
.timeout(Duration::from_secs(30))
|
||||
.user_agent(crate::get_user_agent(crate::ServiceType::Basis));
|
||||
#[cfg(test)]
|
||||
{
|
||||
client_builder = client_builder.no_proxy();
|
||||
}
|
||||
|
||||
// 1. Configure server certificate verification
|
||||
if args.skip_tls_verify {
|
||||
@@ -560,7 +564,6 @@ mod tests {
|
||||
use super::{WebhookArgs, WebhookTarget};
|
||||
use crate::target::{Target, TargetType, decode_object_name};
|
||||
use tokio::net::TcpListener;
|
||||
use tokio::sync::mpsc;
|
||||
use url::Url;
|
||||
use url::form_urlencoded;
|
||||
|
||||
@@ -679,43 +682,37 @@ mod tests {
|
||||
async fn test_is_active_uses_origin_reachability_for_path_endpoints() {
|
||||
let listener = TcpListener::bind("127.0.0.1:0").await.unwrap();
|
||||
let address = listener.local_addr().unwrap();
|
||||
let (path_tx, mut path_rx) = mpsc::channel(1);
|
||||
let accept_task = tokio::spawn(async move {
|
||||
let server = async move {
|
||||
use tokio::io::{AsyncReadExt, AsyncWriteExt};
|
||||
|
||||
let (mut stream, _) = listener.accept().await.unwrap();
|
||||
let mut request = Vec::new();
|
||||
let mut buf = [0u8; 1024];
|
||||
loop {
|
||||
let (mut stream, _) = listener.accept().await.unwrap();
|
||||
let path_tx = path_tx.clone();
|
||||
tokio::spawn(async move {
|
||||
use tokio::io::{AsyncReadExt, AsyncWriteExt};
|
||||
|
||||
let mut request = Vec::new();
|
||||
let mut buf = [0u8; 1024];
|
||||
loop {
|
||||
let read = stream.read(&mut buf).await.unwrap();
|
||||
if read == 0 {
|
||||
break;
|
||||
}
|
||||
request.extend_from_slice(&buf[..read]);
|
||||
if request.windows(4).any(|window| window == b"\r\n\r\n") {
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
let request_line = request
|
||||
.split(|byte| *byte == b'\n')
|
||||
.next()
|
||||
.and_then(|line| std::str::from_utf8(line).ok())
|
||||
.unwrap_or_default()
|
||||
.trim();
|
||||
let path = request_line.split_whitespace().nth(1).unwrap_or_default().to_string();
|
||||
let _ = path_tx.send(path.clone()).await;
|
||||
|
||||
if path == "/" {
|
||||
let response = b"HTTP/1.1 200 OK\r\nContent-Length: 0\r\nConnection: close\r\n\r\n";
|
||||
let _ = stream.write_all(response).await;
|
||||
}
|
||||
});
|
||||
let read = stream.read(&mut buf).await.unwrap();
|
||||
if read == 0 {
|
||||
break;
|
||||
}
|
||||
request.extend_from_slice(&buf[..read]);
|
||||
if request.windows(4).any(|window| window == b"\r\n\r\n") {
|
||||
break;
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
let request_line = request
|
||||
.split(|byte| *byte == b'\n')
|
||||
.next()
|
||||
.and_then(|line| std::str::from_utf8(line).ok())
|
||||
.unwrap_or_default()
|
||||
.trim();
|
||||
let path = request_line.split_whitespace().nth(1).unwrap_or_default().to_string();
|
||||
|
||||
if path == "/" {
|
||||
let response = b"HTTP/1.1 200 OK\r\nContent-Length: 0\r\nConnection: close\r\n\r\n";
|
||||
let _ = stream.write_all(response).await;
|
||||
}
|
||||
path
|
||||
};
|
||||
|
||||
let args = WebhookArgs {
|
||||
endpoint: Url::parse(&format!("http://{address}/hook")).unwrap(),
|
||||
@@ -723,8 +720,8 @@ mod tests {
|
||||
};
|
||||
let target = WebhookTarget::<serde_json::Value>::new("path-probe".to_string(), args).unwrap();
|
||||
|
||||
assert!(target.is_active().await.unwrap());
|
||||
assert_eq!(path_rx.recv().await.unwrap(), "/");
|
||||
accept_task.abort();
|
||||
let (is_active, path) = tokio::join!(target.is_active(), server);
|
||||
assert!(is_active.unwrap());
|
||||
assert_eq!(path, "/");
|
||||
}
|
||||
}
|
||||
|
||||
+4
-2
@@ -33,8 +33,10 @@ services:
|
||||
- RUSTFS_CONSOLE_ADDRESS=0.0.0.0:9001
|
||||
- RUSTFS_CONSOLE_ENABLE=true
|
||||
- RUSTFS_CONSOLE_CORS_ALLOWED_ORIGINS=*
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:?Set RUSTFS_ACCESS_KEY to a non-default value}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:?Set RUSTFS_SECRET_KEY to a non-default value}
|
||||
# SECURITY: these defaults are public and well-known.
|
||||
# Override via env vars before exposing the listener beyond localhost.
|
||||
- RUSTFS_ACCESS_KEY=${RUSTFS_ACCESS_KEY:-rustfsadmin}
|
||||
- RUSTFS_SECRET_KEY=${RUSTFS_SECRET_KEY:-rustfsadmin}
|
||||
- RUSTFS_OBS_LOGGER_LEVEL=info
|
||||
- RUSTFS_TLS_PATH=/opt/tls
|
||||
- RUSTFS_OBS_ENDPOINT=http://otel-collector:4318
|
||||
|
||||
+1
-1
@@ -114,7 +114,7 @@ process_log_directory
|
||||
|
||||
# 4) Default credentials warning
|
||||
if [ "${RUSTFS_ACCESS_KEY:-}" = "rustfsadmin" ] || [ "${RUSTFS_SECRET_KEY:-}" = "rustfsadmin" ]; then
|
||||
echo "!!!WARNING: Default credentials are only allowed on loopback or with explicit insecure local-dev opt-in."
|
||||
echo "!!!WARNING: Using default RUSTFS_ACCESS_KEY or RUSTFS_SECRET_KEY. Override them in production!"
|
||||
fi
|
||||
|
||||
# 5) Append DATA_VOLUMES only if no data paths in arguments
|
||||
|
||||
@@ -24,7 +24,6 @@ use rustfs_config::{
|
||||
};
|
||||
use rustfs_credentials::{DEFAULT_ACCESS_KEY, DEFAULT_SECRET_KEY, Masked};
|
||||
use std::collections::HashSet;
|
||||
use std::net::SocketAddr;
|
||||
use std::sync::{Mutex, OnceLock};
|
||||
|
||||
pub(crate) const LEGACY_ENV_RUSTFS_ROOT_USER: &str = "RUSTFS_ROOT_USER";
|
||||
@@ -179,10 +178,6 @@ impl Config {
|
||||
DEFAULT_ACCESS_KEY.eq(&self.access_key) && DEFAULT_SECRET_KEY.eq(&self.secret_key)
|
||||
}
|
||||
|
||||
pub fn default_credentials_allowed_for_addr(&self, server_addr: SocketAddr, allow_insecure_defaults: bool) -> bool {
|
||||
!self.is_using_default_credentials() || server_addr.ip().is_loopback() || allow_insecure_defaults
|
||||
}
|
||||
|
||||
/// Create Config from Opt
|
||||
pub(super) fn from_opt(opt: Opt) -> std::io::Result<Self> {
|
||||
let Opt {
|
||||
|
||||
@@ -141,24 +141,6 @@ mod tests {
|
||||
assert_eq!(config.buffer_profile, "GeneralPurpose");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn default_credentials_allowed_only_for_loopback_or_explicit_opt_in() {
|
||||
let config = Config::new("0.0.0.0:9000", vec!["/tmp/rustfs-vol1".to_string()]);
|
||||
|
||||
assert!(!config.default_credentials_allowed_for_addr("0.0.0.0:9000".parse().unwrap(), false));
|
||||
assert!(config.default_credentials_allowed_for_addr("127.0.0.1:9000".parse().unwrap(), false));
|
||||
assert!(config.default_credentials_allowed_for_addr("0.0.0.0:9000".parse().unwrap(), true));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn custom_credentials_allowed_on_non_loopback() {
|
||||
let mut config = Config::new("0.0.0.0:9000", vec!["/tmp/rustfs-vol1".to_string()]);
|
||||
config.access_key = "custom-access-key".to_string();
|
||||
config.secret_key = "custom-secret-key".to_string();
|
||||
|
||||
assert!(config.default_credentials_allowed_for_addr("0.0.0.0:9000".parse().unwrap(), false));
|
||||
}
|
||||
|
||||
#[test]
|
||||
#[serial]
|
||||
fn test_custom_console_configuration() {
|
||||
|
||||
+2
-12
@@ -55,7 +55,6 @@ use crate::server::{
|
||||
};
|
||||
use crate::startup_fs_guard::enforce_unsupported_fs_policy;
|
||||
use rustfs_common::{GlobalReadiness, SystemStage, set_global_addr};
|
||||
use rustfs_config::ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS;
|
||||
use rustfs_credentials::init_global_action_credentials;
|
||||
use rustfs_ecstore::store::init_lock_clients;
|
||||
use rustfs_ecstore::{
|
||||
@@ -77,7 +76,7 @@ use rustfs_ecstore::{
|
||||
};
|
||||
use rustfs_iam::init_iam_sys;
|
||||
use rustfs_obs::{init_obs, set_global_guard};
|
||||
use rustfs_utils::{get_env_bool, net::parse_and_resolve_address};
|
||||
use rustfs_utils::net::parse_and_resolve_address;
|
||||
use rustls::crypto::aws_lc_rs::default_provider;
|
||||
use std::net::{IpAddr, Ipv4Addr, Ipv6Addr, SocketAddr};
|
||||
use std::path::{Path, PathBuf};
|
||||
@@ -308,8 +307,7 @@ impl RustFSServerBuilder {
|
||||
// Trusted proxies.
|
||||
rustfs_trusted_proxies::init();
|
||||
|
||||
// Resolve listen address before credential initialization so unsafe
|
||||
// default credentials can fail before the server binds a listener.
|
||||
// Resolve listen address before endpoint/global initialization.
|
||||
let server_addr =
|
||||
parse_and_resolve_address(config.address.as_str()).map_err(|e| ServerError::Init(format!("address: {e}")))?;
|
||||
|
||||
@@ -322,14 +320,6 @@ impl RustFSServerBuilder {
|
||||
));
|
||||
}
|
||||
|
||||
let allow_insecure_defaults = get_env_bool(ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS, false);
|
||||
if !config.default_credentials_allowed_for_addr(server_addr, allow_insecure_defaults) {
|
||||
return Err(ServerError::Init(
|
||||
"default root credentials are not allowed on non-loopback listeners; set access_key and secret_key to non-default values, bind to loopback, or set RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS=true for local development only"
|
||||
.to_string(),
|
||||
));
|
||||
}
|
||||
|
||||
// Credentials.
|
||||
init_global_action_credentials(Some(config.access_key.clone()), Some(config.secret_key.clone()))
|
||||
.map_err(|e| ServerError::Init(format!("credentials: {e:?}")))?;
|
||||
|
||||
+6
-20
@@ -36,7 +36,6 @@ use rustfs::server::{
|
||||
};
|
||||
use rustfs::startup_fs_guard::enforce_unsupported_fs_policy;
|
||||
use rustfs_common::{GlobalReadiness, SystemStage, set_global_addr};
|
||||
use rustfs_config::ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS;
|
||||
use rustfs_credentials::init_global_action_credentials;
|
||||
use rustfs_ecstore::store::init_lock_clients;
|
||||
use rustfs_ecstore::{
|
||||
@@ -62,7 +61,7 @@ use rustfs_iam::{init_iam_sys, init_oidc_sys};
|
||||
use rustfs_obs::{init_metrics_runtime, init_obs, set_global_guard};
|
||||
use rustfs_scanner::init_data_scanner;
|
||||
use rustfs_utils::{
|
||||
ExternalEnvCompatReport, apply_external_env_compat, get_env_bool, get_env_bool_with_aliases, net::parse_and_resolve_address,
|
||||
ExternalEnvCompatReport, apply_external_env_compat, get_env_bool_with_aliases, net::parse_and_resolve_address,
|
||||
};
|
||||
use rustls::crypto::aws_lc_rs::default_provider;
|
||||
use std::io::{Error, Result};
|
||||
@@ -135,12 +134,7 @@ fn is_using_default_credentials(config: &rustfs::config::Config) -> bool {
|
||||
config.is_using_default_credentials()
|
||||
}
|
||||
|
||||
const DEFAULT_CREDENTIALS_WARNING_MESSAGE: &str = "Detected default root credentials; set RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY to non-default values, or use RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS=true only for local development";
|
||||
const DEFAULT_CREDENTIALS_ERROR_MESSAGE: &str = "Default root credentials are not allowed on non-loopback listeners; set RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY to non-default values, bind to loopback, or set RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS=true for local development only";
|
||||
|
||||
fn allow_insecure_default_credentials() -> bool {
|
||||
get_env_bool(ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS, false)
|
||||
}
|
||||
const DEFAULT_CREDENTIALS_WARNING_MESSAGE: &str = "Detected default root credentials; set RUSTFS_ACCESS_KEY and RUSTFS_SECRET_KEY to non-default values for production deployments";
|
||||
|
||||
async fn async_main() -> Result<()> {
|
||||
// Parse command line arguments
|
||||
@@ -275,11 +269,6 @@ async fn run(config: rustfs::config::Config) -> Result<()> {
|
||||
let server_port = server_addr.port();
|
||||
let server_address = server_addr.to_string();
|
||||
|
||||
if !config.default_credentials_allowed_for_addr(server_addr, allow_insecure_default_credentials()) {
|
||||
error!("{DEFAULT_CREDENTIALS_ERROR_MESSAGE}");
|
||||
return Err(Error::other(DEFAULT_CREDENTIALS_ERROR_MESSAGE));
|
||||
}
|
||||
|
||||
if is_using_default_credentials(&config) {
|
||||
warn!("{}", DEFAULT_CREDENTIALS_WARNING_MESSAGE);
|
||||
}
|
||||
@@ -826,12 +815,9 @@ mod tests {
|
||||
|
||||
#[test]
|
||||
fn default_credentials_messages_are_actionable_without_exposing_values() {
|
||||
for message in [DEFAULT_CREDENTIALS_WARNING_MESSAGE, DEFAULT_CREDENTIALS_ERROR_MESSAGE] {
|
||||
assert!(message.contains(rustfs_config::ENV_RUSTFS_ACCESS_KEY));
|
||||
assert!(message.contains(rustfs_config::ENV_RUSTFS_SECRET_KEY));
|
||||
assert!(message.contains(ENV_RUSTFS_ALLOW_INSECURE_DEFAULT_CREDENTIALS));
|
||||
assert!(!message.contains(rustfs_credentials::DEFAULT_ACCESS_KEY));
|
||||
assert!(!message.contains(rustfs_credentials::DEFAULT_SECRET_KEY));
|
||||
}
|
||||
assert!(DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_config::ENV_RUSTFS_ACCESS_KEY));
|
||||
assert!(DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_config::ENV_RUSTFS_SECRET_KEY));
|
||||
assert!(!DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_credentials::DEFAULT_ACCESS_KEY));
|
||||
assert!(!DEFAULT_CREDENTIALS_WARNING_MESSAGE.contains(rustfs_credentials::DEFAULT_SECRET_KEY));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
RUSTFS_ACCESS_KEY=rustfs-dev-admin
|
||||
RUSTFS_SECRET_KEY=rustfs-dev-secret
|
||||
RUSTFS_ACCESS_KEY=rustfsadmin
|
||||
RUSTFS_SECRET_KEY=rustfsadmin
|
||||
|
||||
RUSTFS_VOLUMES="http://node{1...4}:7000/data/rustfs{0...3} http://node{5...8}:7000/data/rustfs{0...3}"
|
||||
RUSTFS_ADDRESS=":7000"
|
||||
|
||||
+4
-4
@@ -20,16 +20,16 @@ VOLUME=$2
|
||||
chmod +x $BIN
|
||||
mkdir -p $VOLUME
|
||||
|
||||
export RUSTFS_ACCESS_KEY="${RUSTFS_ACCESS_KEY:-rustfsadmin}"
|
||||
export RUSTFS_SECRET_KEY="${RUSTFS_SECRET_KEY:-rustfsadmin}"
|
||||
export RUST_LOG="rustfs=debug,ecstore=debug,s3s=debug,iam=debug"
|
||||
export RUST_BACKTRACE=full
|
||||
export RUSTFS_ACCESS_KEY=rustfs-e2e-admin
|
||||
export RUSTFS_SECRET_KEY=rustfs-e2e-secret
|
||||
$BIN $VOLUME > /tmp/rustfs.log 2>&1 &
|
||||
|
||||
sleep 10
|
||||
|
||||
export AWS_ACCESS_KEY_ID=$RUSTFS_ACCESS_KEY
|
||||
export AWS_SECRET_ACCESS_KEY=$RUSTFS_SECRET_KEY
|
||||
export AWS_ACCESS_KEY_ID="${RUSTFS_ACCESS_KEY:-rustfsadmin}"
|
||||
export AWS_SECRET_ACCESS_KEY="${RUSTFS_SECRET_KEY:-rustfsadmin}"
|
||||
export AWS_REGION=us-east-1
|
||||
export AWS_ENDPOINT_URL=http://localhost:9000
|
||||
export RUST_LOG="s3s_e2e=debug,s3s_test=info,s3s=debug"
|
||||
|
||||
@@ -134,7 +134,7 @@ start_rustfs() {
|
||||
|
||||
# Start RustFS in background with environment variables
|
||||
cd "$TARGET_DIR"
|
||||
RUSTFS_ACCESS_KEY=rustfs-e2e-admin RUSTFS_SECRET_KEY=rustfs-e2e-secret \
|
||||
RUSTFS_ACCESS_KEY=rustfsadmin RUSTFS_SECRET_KEY=rustfsadmin \
|
||||
RUSTFS_OBS_LOG_DIRECTORY="$TARGET_DIR/logs" \
|
||||
./rustfs --address :9000 "$DATA_DIR" > rustfs.log 2>&1 &
|
||||
RUSTFS_PID=$!
|
||||
|
||||
@@ -15,8 +15,8 @@ PRECHECK_AUTO_CLEANUP="${PRECHECK_AUTO_CLEANUP:-true}"
|
||||
WAIT_PROBE_MODE="${WAIT_PROBE_MODE:-service}"
|
||||
COMPOSE_UP_NO_BUILD="${COMPOSE_UP_NO_BUILD:-false}"
|
||||
|
||||
RUSTFS_ACCESS_KEY="${RUSTFS_ACCESS_KEY:-rustfs-cluster-admin}"
|
||||
RUSTFS_SECRET_KEY="${RUSTFS_SECRET_KEY:-rustfs-cluster-secret}"
|
||||
RUSTFS_ACCESS_KEY="${RUSTFS_ACCESS_KEY:-rustfsadmin}"
|
||||
RUSTFS_SECRET_KEY="${RUSTFS_SECRET_KEY:-rustfsadmin}"
|
||||
RUSTFS_DOCKER_PLATFORM="${RUSTFS_DOCKER_PLATFORM:-}"
|
||||
RUSTFS_OBS_ENDPOINT="${RUSTFS_OBS_ENDPOINT:-}"
|
||||
RUSTFS_UNSAFE_BYPASS_DISK_CHECK="${RUSTFS_UNSAFE_BYPASS_DISK_CHECK:-true}"
|
||||
|
||||
@@ -130,8 +130,8 @@ DEPLOY_MODE=existing S3_HOST=192.168.1.100 S3_PORT=9000 ./scripts/s3-tests/run.s
|
||||
|
||||
### Service Configuration
|
||||
|
||||
- `S3_ACCESS_KEY`: Main user access key (default: `rustfs-ci-admin`)
|
||||
- `S3_SECRET_KEY`: Main user secret key (default: `rustfs-ci-secret`)
|
||||
- `S3_ACCESS_KEY`: Main user access key (default: `rustfsadmin`)
|
||||
- `S3_SECRET_KEY`: Main user secret key (default: `rustfsadmin`)
|
||||
- `S3_ALT_ACCESS_KEY`: Alt user access key (default: `rustfsalt`)
|
||||
- `S3_ALT_SECRET_KEY`: Alt user secret key (default: `rustfsalt`)
|
||||
- `S3_REGION`: S3 region (default: `us-east-1`)
|
||||
@@ -420,8 +420,8 @@ curl http://192.168.1.100:9000/health
|
||||
|
||||
# Verify S3 API is responding
|
||||
awscurl --service s3 --region us-east-1 \
|
||||
--access_key rustfs-ci-admin \
|
||||
--secret_key rustfs-ci-secret \
|
||||
--access_key rustfsadmin \
|
||||
--secret_key rustfsadmin \
|
||||
-X GET "http://192.168.1.100:9000/"
|
||||
```
|
||||
|
||||
|
||||
@@ -25,8 +25,8 @@ PYTHON_VERSION=$(python3 -c "import sys; print(f'{sys.version_info.major}.{sys.v
|
||||
export PATH="$HOME/Library/Python/${PYTHON_VERSION}/bin:$HOME/.local/bin:$PATH"
|
||||
|
||||
# Configuration
|
||||
S3_ACCESS_KEY="${S3_ACCESS_KEY:-rustfs-ci-admin}"
|
||||
S3_SECRET_KEY="${S3_SECRET_KEY:-rustfs-ci-secret}"
|
||||
S3_ACCESS_KEY="${S3_ACCESS_KEY:-rustfsadmin}"
|
||||
S3_SECRET_KEY="${S3_SECRET_KEY:-rustfsadmin}"
|
||||
S3_ALT_ACCESS_KEY="${S3_ALT_ACCESS_KEY:-rustfsalt}"
|
||||
S3_ALT_SECRET_KEY="${S3_ALT_SECRET_KEY:-rustfsalt}"
|
||||
S3_REGION="${S3_REGION:-us-east-1}"
|
||||
@@ -218,8 +218,8 @@ Environment Variables:
|
||||
RUSTFS_BINARY - Path to RustFS binary (for binary mode, default: ./target/release/rustfs)
|
||||
S3_HOST - S3 service host (default: 127.0.0.1)
|
||||
S3_PORT - S3 service port (default: 9000)
|
||||
S3_ACCESS_KEY - Main user access key (default: rustfs-ci-admin)
|
||||
S3_SECRET_KEY - Main user secret key (default: rustfs-ci-secret)
|
||||
S3_ACCESS_KEY - Main user access key (default: rustfsadmin)
|
||||
S3_SECRET_KEY - Main user secret key (default: rustfsadmin)
|
||||
S3_ALT_ACCESS_KEY - Alt user access key (default: rustfsalt)
|
||||
S3_ALT_SECRET_KEY - Alt user secret key (default: rustfsalt)
|
||||
MAXFAIL - Stop after N failures (default: 1)
|
||||
@@ -690,7 +690,7 @@ envsubst < "${TEMPLATE_PATH}" > "${CONF_OUTPUT_PATH}" || {
|
||||
}
|
||||
|
||||
# Step 7: Provision s3-tests alt user
|
||||
# Note: The configured main user is a system user and doesn't need to be created via API
|
||||
# Note: Main user (rustfsadmin) is a system user and doesn't need to be created via API
|
||||
log_info "Provisioning s3-tests alt user..."
|
||||
|
||||
# Helper function to install Python packages with fallback for externally-managed environments
|
||||
|
||||
Reference in New Issue
Block a user