Project

General

Profile

Actions

Feature #18015

closed

Ability to limit keep access to system components

Added by Peter Amstutz over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Assigned To:
-
Category:
-
Target version:
-
Story points:
-

Description

User needs to restrict ability to get blocks from keep to system components only (keep-web, crunch-run?). Boundary security via keepproxy (as implemented in #17464) turns out to not be a solution because the private network is shared by multiple clusters and users, and they would like to limit the use of arv-mount on the shell node.


Related issues

Related to Arvados - Idea #17464: Logging and restricting downloads in keep-web and keepproxyResolvedPeter Amstutz06/15/2021Actions
Actions

Also available in: Atom PDF