You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@mesos.apache.org by "Adam B (JIRA)" <ji...@apache.org> on 2016/04/26 10:37:12 UTC

[jira] [Updated] (MESOS-4843) Authorize Master Operator Endpoints

     [ https://issues.apache.org/jira/browse/MESOS-4843?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Adam B updated MESOS-4843:
--------------------------
    Labels: authorization mesosphere security  (was: mesosphere security)

> Authorize Master Operator Endpoints
> -----------------------------------
>
>                 Key: MESOS-4843
>                 URL: https://issues.apache.org/jira/browse/MESOS-4843
>             Project: Mesos
>          Issue Type: Epic
>          Components: master, security
>            Reporter: Adam B
>            Assignee: Joerg Schad
>              Labels: authorization, mesosphere, security
>
> In a secure, multi-tenant cluster, the operator doesn't want to give every user access to read or modify cluster state/config, nor to perform administrative actions. As such, we need to make sure that all such endpoints are authenticated and authorized.
> We've already added authorization to some operator endpoints (/teardown, /reserve, etc.), but many remain unsecured.
> - /roles, /observe, /registrar, /state-summary
> - /maintenance, /machine,
> - /logging, /profiler, /metrics, /flags, /system/stats.json
> - Leave open? /redirect, /health, /version
> See http://mesos.apache.org/documentation/latest/endpoints/ for a more complete list. Some endpoints (e.g. state.json) will need a finer-grained authz.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)