dheeraj12347 commented on PR #14053:
URL: https://github.com/apache/cloudstack/pull/14053#issuecomment-5535771677

   Hi @wido, @DaanHoogland and Mitchell Drage,
   
   I’ve prepared a design-only PR based on the per-bucket object storage 
credentials and key rotation discussion:
   
   https://github.com/apache/cloudstack/pull/14053
   
   The proposal covers the per-bucket credential model, two-key rotation, 
revocation, API/persistence changes, backward compatibility, migration, 
provider impact, and security considerations.
   
   I’ve intentionally left the implementation out for now so the design and 
open architectural questions can be reviewed first.
   
   I’d especially appreciate your feedback on the credential model, rotation 
semantics, migration approach, and whether per-bucket credentials should be the 
default for new buckets or initially opt-in.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to