dheeraj12347 commented on PR #14053: URL: https://github.com/apache/cloudstack/pull/14053#issuecomment-5535771677
Hi @wido, @DaanHoogland and Mitchell Drage, I’ve prepared a design-only PR based on the per-bucket object storage credentials and key rotation discussion: https://github.com/apache/cloudstack/pull/14053 The proposal covers the per-bucket credential model, two-key rotation, revocation, API/persistence changes, backward compatibility, migration, provider impact, and security considerations. I’ve intentionally left the implementation out for now so the design and open architectural questions can be reviewed first. I’d especially appreciate your feedback on the credential model, rotation semantics, migration approach, and whether per-bucket credentials should be the default for new buckets or initially opt-in. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
