Identity Policies for NFS and SMB Access

Prev Next

Intro

Identity Policies (and Bucket Policies) can be used to control NFS and SMB access for users and groups.  This is especially useful when additional users and/or groups need access to existing datasets with a large number of files or objects, without requiring recursive ACL changes to each file and directory.  This also allows permissions to be set by policy rather than by individual users and owners.

The mapping of S3 Actions to RPC Calls can be found by searching for “Controlling File and Directory Permissions Across Protocols” in The VAST Cluster Administrator’s Guide.

NOTE: These could also be defined as Bucket Policies.

Requirements:

A View must have S3 Bucket as a protocol, and the bucket name must match the Identity Policy.

The View Policy must be using a Security Flavor of S3 Native

It is suggested that S3 ACLs be disabled for the View.  This matches AWS's default behavior and prevents ACLs from granting additional access beyond these policies.

The examples below cover NFSv3, NFSv4.1, and SMB Access.

NOTE: Permissions and ACLs related to allowed/denied users or groups will not be visible to the end user via NFS or SMB protcols

Read-Only Access for NFS

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Allow NFS RO",
      "Action": [
        "s3:HeadBucket",
    	"s3:GetObject",
    	"s3:GetObjectAcl",
        "s3:HeadObject",
        "s3:ListObjects",
    	"s3:ListObjectsV2"
      ],
      "Effect": "Allow",
      "Resource": [
        "s3-nfs-bucket",
        "s3-nfs-bucket/*"
      ]
    }
  ]
}

Read-Write Access for NFS

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Allow NFS RW",
      "Action": [
        "s3:HeadBucket",
        "s3:ListObjects",
    	"s3:ListObjectsV2",
        "s3:HeadObject",
    	"s3:GetObject",
    	"s3:PutObject",
    	"s3:DeleteObject",
    	"s3:GetObjectAcl",
        "s3:PutObjectAcl"	
      ],
      "Effect": "Allow",
      "Resource": [
        "s3-nfs-bucket",
        "s3-nfs-bucket/*"
      ]
    }
  ]
}

SMB Read-Only Access

NOTE: Effectively the same as NFS but also requires s3:ListBucket to satisfy the FILE_LIST_DIRECTORY action.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Allow Reads",
      "Action": [
        "s3:HeadBucket",
    	"s3:ListBucket",
    	"s3:GetObject",
    	"s3:GetObjectAcl",
        "s3:HeadObject",
        "s3:ListObjects",
    	"s3:ListObjectsV2"
      ],
      "Effect": "Allow",
      "Resource": [
        "s3-smb-bucket",
        "s3-smb-bucket/*"
      ]
    }
  ]
}

SMB Read-Write Access

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Allow Reads",
      "Action": [
        "s3:HeadBucket",
    	"s3:ListBucket",
        "s3:ListObjects",
    	"s3:ListObjectsV2",
        "s3:HeadObject",
    	"s3:GetObject",
    	"s3:PutObject",
    	"s3:DeleteObject",
    	"s3:GetObjectAcl",
        "s3:PutObjectAcl"	
      ],
      "Effect": "Allow",
      "Resource": [
        "s3-smb-bucket",
        "s3-smb-bucket/*"
      ]
    }
  ]
}