mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-11 07:36:53 +00:00
feat(kms): add AppRole configuration surface for Vault auth
Extend VaultAuthMethod::AppRole with secret_id_file (re-read on every login so external rotation is picked up), a configurable auth mount (default "approle"), and an optional fail-closed safety window. All new fields are serde(default) so previously persisted configurations keep deserializing, and the strict admin-configure deserializer accepts them as optional. Environment selection: setting RUSTFS_KMS_VAULT_APPROLE_ROLE_ID switches both Vault backends to AppRole; the secret_id comes from RUSTFS_KMS_VAULT_APPROLE_SECRET_ID_FILE (path stored, file wins) or RUSTFS_KMS_VAULT_APPROLE_SECRET_ID, following the static secret-key file precedent. validate() rejects AppRole configs without a role_id, without any secret_id source, or with an empty mount. Also append the CredentialsUnavailable error variant used by the fail-closed credential gate.
This commit is contained in:
@@ -128,6 +128,11 @@ pub enum KmsError {
|
||||
/// Backup/restore bundle contract violation; see [`crate::backup::BackupError`]
|
||||
#[error(transparent)]
|
||||
Backup(#[from] crate::backup::BackupError),
|
||||
|
||||
/// Backend credentials expired or could not be refreshed in time; requests
|
||||
/// fail closed instead of being sent with credentials that may lapse mid-flight
|
||||
#[error("KMS credentials unavailable: {message}")]
|
||||
CredentialsUnavailable { message: String },
|
||||
}
|
||||
|
||||
impl KmsError {
|
||||
@@ -269,6 +274,11 @@ impl KmsError {
|
||||
version,
|
||||
}
|
||||
}
|
||||
|
||||
/// Create a credentials unavailable error
|
||||
pub fn credentials_unavailable<S: Into<String>>(message: S) -> Self {
|
||||
Self::CredentialsUnavailable { message: message.into() }
|
||||
}
|
||||
}
|
||||
|
||||
/// Convert from standard library errors
|
||||
|
||||
Reference in New Issue
Block a user