Our team used a workflow similar to this for MinIO mc:
mc alias set local http://localhost:9001 root rootroot
mc mb local/my-bucket
mc anonymous set public "local/my-bucket/persons/music/**"
mc anonymous set public "local/my-bucket/profiles/images/**"
mc anonymous get-json local/my-bucket
Result json policy:
{
"Statement": [
{
"Action": [
"s3:GetBucketLocation",
"s3:ListBucketMultipartUploads"
],
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Resource": [
"arn:aws:s3:::my-bucket"
]
},
{
"Action": [
"s3:ListBucket"
],
"Condition": {
"StringEquals": {
"s3:prefix": [
"persons/music/**",
"profiles/images/**"
]
}
},
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Resource": [
"arn:aws:s3:::my-bucket"
]
},
{
"Action": [
"s3:AbortMultipartUpload",
"s3:DeleteObject",
"s3:GetObject",
"s3:ListMultipartUploadParts",
"s3:PutObject"
],
"Effect": "Allow",
"Principal": {
"AWS": [
"*"
]
},
"Resource": [
"arn:aws:s3:::my-bucket/persons/music/***",
"arn:aws:s3:::my-bucket/profiles/images/***"
]
}
],
"Version": "2012-10-17"
}
After MinIO free Docker images deletion, we decided to switch to RustFS using rc:
rc alias set local http://localhost:9000 root rootroot
rc mb local/my-bucket
rc anonymous set public "local/my-bucket/persons/music"
rc anonymous set public "local/my-bucket/profiles/images"
rc anonymous get-json local/my-bucket
And we get this json policy:
{
"Statement": [
{
"Action": [
"s3:GetObject"
],
"Effect": "Allow",
"Principal": "*",
"Resource": "arn:aws:s3:::my-bucket/profiles/images/*",
"Sid": "AnonymousRead1"
},
{
"Action": "s3:ListBucket",
"Condition": {
"StringLike": {
"s3:prefix": [
"profiles/images",
"profiles/images/*",
"profiles/images*"
]
}
},
"Effect": "Allow",
"Principal": "*",
"Resource": "arn:aws:s3:::my-bucket",
"Sid": "AnonymousList2"
},
{
"Action": [
"s3:PutObject"
],
"Effect": "Allow",
"Principal": "*",
"Resource": "arn:aws:s3:::my-bucket/profiles/images/*",
"Sid": "AnonymousWrite3"
}
],
"Version": "2012-10-17"
}
(Public access to persons/music has been lost)
This slightly disrupted our transition from mc to rc; we had to add a json file and use anonymous set-json command instead.
Is it possible to update the rc so that it extends the existing policy for the bucket rather than overwriting it completely? I noticed there’s a warning message about this when using the cli (Warning: setting 'local/my-bucket/profiles/images' will replace the entire bucket policy for 'my-bucket', which may remove unrelated statements). Is this restriction really necessary?
Our team used a workflow similar to this for MinIO
mc:Result json policy:
{ "Statement": [ { "Action": [ "s3:GetBucketLocation", "s3:ListBucketMultipartUploads" ], "Effect": "Allow", "Principal": { "AWS": [ "*" ] }, "Resource": [ "arn:aws:s3:::my-bucket" ] }, { "Action": [ "s3:ListBucket" ], "Condition": { "StringEquals": { "s3:prefix": [ "persons/music/**", "profiles/images/**" ] } }, "Effect": "Allow", "Principal": { "AWS": [ "*" ] }, "Resource": [ "arn:aws:s3:::my-bucket" ] }, { "Action": [ "s3:AbortMultipartUpload", "s3:DeleteObject", "s3:GetObject", "s3:ListMultipartUploadParts", "s3:PutObject" ], "Effect": "Allow", "Principal": { "AWS": [ "*" ] }, "Resource": [ "arn:aws:s3:::my-bucket/persons/music/***", "arn:aws:s3:::my-bucket/profiles/images/***" ] } ], "Version": "2012-10-17" }After MinIO free Docker images deletion, we decided to switch to RustFS using
rc:And we get this json policy:
{ "Statement": [ { "Action": [ "s3:GetObject" ], "Effect": "Allow", "Principal": "*", "Resource": "arn:aws:s3:::my-bucket/profiles/images/*", "Sid": "AnonymousRead1" }, { "Action": "s3:ListBucket", "Condition": { "StringLike": { "s3:prefix": [ "profiles/images", "profiles/images/*", "profiles/images*" ] } }, "Effect": "Allow", "Principal": "*", "Resource": "arn:aws:s3:::my-bucket", "Sid": "AnonymousList2" }, { "Action": [ "s3:PutObject" ], "Effect": "Allow", "Principal": "*", "Resource": "arn:aws:s3:::my-bucket/profiles/images/*", "Sid": "AnonymousWrite3" } ], "Version": "2012-10-17" }(Public access to
persons/musichas been lost)This slightly disrupted our transition from
mctorc; we had to add ajsonfile and useanonymous set-jsoncommand instead.Is it possible to update the
rcso that it extends the existing policy for the bucket rather than overwriting it completely? I noticed there’s a warning message about this when using the cli (Warning: setting 'local/my-bucket/profiles/images' will replace the entire bucket policy for 'my-bucket', which may remove unrelated statements). Is this restriction really necessary?