[
https://issues.apache.org/jira/browse/MESOS-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Gavin updated MESOS-4843:
-------------------------
Comment: was deleted
(was: www.rtat.net)
> Authorize Master Operator Endpoints
> -----------------------------------
>
> Key: MESOS-4843
> URL: https://issues.apache.org/jira/browse/MESOS-4843
> Project: Mesos
> Issue Type: Epic
> Components: master, security
> Reporter: Adam B
> Priority: Major
> Labels: authorization, mesosphere, security
> Fix For: 1.0.0
>
>
> In a secure, multi-tenant cluster, the operator doesn't want to give every
> user access to read or modify cluster state/config, nor to perform
> administrative actions. As such, we need to make sure that all such endpoints
> are authenticated and authorized.
> We've already added authorization to some operator endpoints (/teardown,
> /reserve, etc.), but many remain unsecured.
> - /roles, /observe, /registrar, /state-summary
> - /maintenance, /machine,
> - /logging, /profiler, /metrics, /flags, /system/stats.json
> - Leave open? /redirect, /health, /version
> See http://mesos.apache.org/documentation/latest/endpoints/ for a more
> complete list. Some endpoints (e.g. state.json) will need a finer-grained
> authz.
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)