feat(storage): organize storage credential configs for security - #19147
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
7d22460 to
726bd10
Compare
d9b0c36 to
145421c
Compare
145421c to
cd23ebb
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Docker Image for PR
|
Docker Image for PR
|
Docker Image for PR
|
|
@codex review |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
When allow_insecure is true in storage config, enable the credential chain so EC2 instance metadata (IMDS) can provide IAM role credentials. This was removed in ebcad91 (databendlabs#19147), causing ATTACH TABLE to fail with 403 when relying on EC2 IAM role without explicit AK/SK.
I hereby agree to the terms of the CLA available at: https://docs.databend.com/dev/policies/cla/
Summary
Added global credential-chain controls:
StorageConfignow exposes runtime-onlydisable_config_loadanddisable_instance_profile, andCredentialChainConfigreplaces the previous S3-specific helper soDataOperatorseeds the standardized policy for every storage operator instance.Tightened stage runtime policy:
StageInfocarries a non-persistedallow_credential_chainflag,init_stage_operatorhonors it alongsiderole_arn, and the system history stage is auto-opted in while other stages stay locked down unless they explicitly require the ambient chain.For compatibility, the existing
disable_credential_loaderfield is treated as "disallow credential chain".Tests
cargo check)Type of change
This change is