Ethan Rose created HDDS-16369:
---------------------------------

             Summary: Add internal protocol ACL settings to docs
                 Key: HDDS-16369
                 URL: https://issues.apache.org/jira/browse/HDDS-16369
             Project: Apache Ozone
          Issue Type: Improvement
          Components: documentation
            Reporter: Ethan Rose


The following internal configurations default to {{*}}, but need to be 
restricted to the principals of the services that need to access them:

{code}
hdds.security.client.datanode.container.protocol.acl
hdds.security.client.datanode.disk.balancer.protocol.acl
hdds.security.client.scm.block.protocol.acl
hdds.security.client.scm.certificate.protocol.acl
hdds.security.client.scm.container.protocol.acl
hdds.security.client.scm.secretkey.datanode.protocol.acl
hdds.security.client.scm.secretkey.om.protocol.acl
ozone.om.security.admin.protocol.acl
ozone.om.security.client.protocol.acl
ozone.recon.security.client.datanode.container.protocol.acl
ozone.security.reconfigure.protocol.acl
{code}

There may be more, this is just what I found with a quick code grep. We need to 
update [the 
docs|https://ozone.apache.org/docs/administrator-guide/configuration/security/] 
to specify how these should be set in a secure deployment.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to