mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-09 14:49:25 +00:00
cad8246ffb
* test(kms): add a scripted loopback Vault for policy wiring tests A minimal HTTP/1.1 responder that serves canned Vault responses in order and records the method/path sequence, so wiring tests can assert exactly how many requests a code path performed (retries, read-confirm) without a live Vault server. * feat(kms): route Vault operations through the retry policy engine Wire every outbound vaultrs call in the KV2 and Transit backends through policy::execute, completing the wiring half of the operation policy work (the engine landed separately): - Reads (KV2 read/read_metadata/read_version/list, transit read/list/ encrypt/decrypt, health checks) run as ReadIdempotent: bounded retries with exponential backoff and jitter on 429, recoverable 5xx, and connection-level failures; 400/401/403/404 stay fatal. - Writes (KV2 set/CAS set/delete_metadata, transit create/update/rotate/ delete, metadata writes) run as MutatingNonIdempotent: exactly one attempt under the per-attempt timeout, never replayed. CAS conflicts in the rotation protocol pass through unchanged as the concurrency signal they are. - Each attempt takes a fresh credential snapshot, so a retry after a credential rotation uses the new token. - Read-confirm recovery for lost create responses: when a create finds an existing key that is exactly what it would have produced (same algorithm, enabled, usable material, and for request-level creates the same usage/description/tags), it reports the stored key as the create result instead of KeyAlreadyExists. Any divergence keeps failing. - Deletes treat already-deleted records as completed deletes (KV2 version records; transit metadata already did), so re-running an interrupted deletion converges. - A failed existence pre-check inside create now fails the create instead of falling through to a blind overwrite (fail closed). - The policy module sheds its allow(dead_code) now that it is wired. Wiring tests run against a scripted loopback Vault and assert request counts and endpoints for the retry, single-attempt, CAS-conflict, and read-confirm paths. Refs rustfs/backlog#1569 (part of rustfs/backlog#1562)
83 lines
2.8 KiB
TOML
83 lines
2.8 KiB
TOML
# Copyright 2024 RustFS Team
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
[package]
|
|
name = "rustfs-kms"
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
repository.workspace = true
|
|
rust-version.workspace = true
|
|
version.workspace = true
|
|
homepage.workspace = true
|
|
description = "Key Management Service for RustFS, providing secure key generation, storage, and object encryption capabilities."
|
|
keywords = ["kms", "encryption", "key-management", "rustfs", "security"]
|
|
categories = ["cryptography", "web-programming", "authentication"]
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
# Core dependencies
|
|
async-trait = { workspace = true }
|
|
tokio = { workspace = true, features = ["fs", "io-util", "macros", "rt-multi-thread", "sync", "time"] }
|
|
uuid = { workspace = true, features = ["serde", "v4", "fast-rng", "macro-diagnostics"] }
|
|
jiff = { workspace = true, features = ["serde"] }
|
|
serde = { workspace = true, features = ["derive"] }
|
|
serde_json = { workspace = true, features = ["raw_value"] }
|
|
tracing = { workspace = true }
|
|
thiserror = { workspace = true }
|
|
|
|
# Cryptography
|
|
aes-gcm = { workspace = true, features = ["rand_core"] }
|
|
argon2 = { workspace = true }
|
|
chacha20poly1305 = { workspace = true }
|
|
rand = { workspace = true, features = ["serde"] }
|
|
base64 = { workspace = true }
|
|
hex = { workspace = true }
|
|
sha2 = { workspace = true }
|
|
subtle = { workspace = true }
|
|
zeroize = { workspace = true, features = ["derive"] }
|
|
|
|
# Configuration and storage
|
|
url = { workspace = true }
|
|
tempfile = { workspace = true }
|
|
|
|
# Caching
|
|
moka = { workspace = true, features = ["future"] }
|
|
|
|
# Additional dependencies
|
|
md-5 = { workspace = true }
|
|
arc-swap = { workspace = true }
|
|
rustfs-utils = { workspace = true }
|
|
rustfs-security-governance = { workspace = true }
|
|
|
|
# HTTP client for Vault
|
|
reqwest = { workspace = true }
|
|
vaultrs = { workspace = true }
|
|
# vaultrs surfaces transport-level failures as wrapped rustify errors; the
|
|
# operation policy needs the concrete type to classify them for retry decisions.
|
|
rustify = { workspace = true }
|
|
tokio-util = { workspace = true }
|
|
|
|
[dev-dependencies]
|
|
anyhow = { workspace = true }
|
|
insta = { workspace = true, features = ["yaml", "json"] }
|
|
tempfile = { workspace = true }
|
|
temp-env = { workspace = true }
|
|
# "net" backs the scripted loopback Vault used by the policy wiring tests.
|
|
tokio = { workspace = true, features = ["net", "test-util"] }
|
|
|
|
[features]
|
|
default = []
|