Dear All
Is it possible to define s3 bucket policies with the Principal ("arn:aws:iam:::user/parentusera") on a subuser - level instead of user - level? I did a test with Nautilus (14.2.4-373) with a user 'parentusera'
and a subuser 'subusera'. radosgw-admin user info --uid=parentusera
The following bucket policy is applied on a bucket (owned by
another user), in order to let 'subusera' access it: The Principal "arn:aws:iam:::user/parentusera" is actually matching all subusers of 'parentusera' and 'parentusera' itself. Is it possible to match a single subuser? I made some tries like:
But no luck. I think the problem comes from the regex which disallows ':' for
the username: Maybe a solution would be to use '/' as separator for subusers
instead of ':' ?
Best Regards Francois Scheurer
-- EveryWare AG François Scheurer Senior Systems Engineer Zurlindenstrasse 52a CH-8003 Zürich tel: +41 44 466 60 00 fax: +41 44 466 60 10 mail: francois.scheurer@xxxxxxxxxxxx web: http://www.everyware.ch |
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ ceph-users mailing list ceph-users@xxxxxxxxxxxxxx http://lists.ceph.com/listinfo.cgi/ceph-users-ceph.com