-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add encryption support for repository #9289
Add encryption support for repository #9289
Conversation
Gradle Check (Jenkins) Run Completed with:
|
Compatibility status:
|
server/src/main/java/org/opensearch/cluster/metadata/RepositoryMetadata.java
Outdated
Show resolved
Hide resolved
plugins/repository-s3/src/main/java/org/opensearch/repositories/s3/S3BlobContainer.java
Outdated
Show resolved
Hide resolved
server/src/main/java/org/opensearch/common/blobstore/EncryptedBlobContainer.java
Outdated
Show resolved
Hide resolved
Compatibility status:Checks if related components are compatible with change d3b938b Incompatible componentsIncompatible components: [https://github.com/opensearch-project/anomaly-detection.git, https://github.com/opensearch-project/sql.git, https://github.com/opensearch-project/neural-search.git] Skipped componentsCompatible componentsCompatible components: [https://github.com/opensearch-project/security.git, https://github.com/opensearch-project/alerting.git, https://github.com/opensearch-project/index-management.git, https://github.com/opensearch-project/asynchronous-search.git, https://github.com/opensearch-project/job-scheduler.git, https://github.com/opensearch-project/observability.git, https://github.com/opensearch-project/common-utils.git, https://github.com/opensearch-project/k-nn.git, https://github.com/opensearch-project/reporting.git, https://github.com/opensearch-project/cross-cluster-replication.git, https://github.com/opensearch-project/geospatial.git, https://github.com/opensearch-project/notifications.git, https://github.com/opensearch-project/ml-commons.git, https://github.com/opensearch-project/performance-analyzer.git, https://github.com/opensearch-project/performance-analyzer-rca.git, https://github.com/opensearch-project/security-analytics.git, https://github.com/opensearch-project/opensearch-oci-object-storage.git] |
Gradle Check (Jenkins) Run Completed with:
|
Signed-off-by: Vikas Bansal <43470111+vikasvb90@users.noreply.github.com>
Compatibility status:Checks if related components are compatible with change bfb49b9 Incompatible componentsIncompatible components: [https://github.com/opensearch-project/anomaly-detection.git, https://github.com/opensearch-project/sql.git, https://github.com/opensearch-project/neural-search.git] Skipped componentsCompatible componentsCompatible components: [https://github.com/opensearch-project/security.git, https://github.com/opensearch-project/alerting.git, https://github.com/opensearch-project/index-management.git, https://github.com/opensearch-project/job-scheduler.git, https://github.com/opensearch-project/asynchronous-search.git, https://github.com/opensearch-project/observability.git, https://github.com/opensearch-project/common-utils.git, https://github.com/opensearch-project/k-nn.git, https://github.com/opensearch-project/reporting.git, https://github.com/opensearch-project/cross-cluster-replication.git, https://github.com/opensearch-project/geospatial.git, https://github.com/opensearch-project/performance-analyzer.git, https://github.com/opensearch-project/notifications.git, https://github.com/opensearch-project/ml-commons.git, https://github.com/opensearch-project/performance-analyzer-rca.git, https://github.com/opensearch-project/security-analytics.git, https://github.com/opensearch-project/opensearch-oci-object-storage.git] |
Gradle Check (Jenkins) Run Completed with:
|
Codecov Report
@@ Coverage Diff @@
## main #9289 +/- ##
============================================
- Coverage 71.07% 71.06% -0.01%
- Complexity 57730 57776 +46
============================================
Files 4806 4814 +8
Lines 272238 272660 +422
Branches 39729 39783 +54
============================================
+ Hits 193480 193779 +299
- Misses 62531 62556 +25
- Partials 16227 16325 +98
|
The backport to
To backport manually, run these commands in your terminal: # Navigate to the root of your repository
cd $(git rev-parse --show-toplevel)
# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add ../.worktrees/OpenSearch/backport-2.x 2.x
# Navigate to the new working tree
pushd ../.worktrees/OpenSearch/backport-2.x
# Create a new branch
git switch --create backport/backport-9289-to-2.x
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 63ce8324b5a4a2d1afa3f76c1dd758f55f4cd0e8
# Push it to GitHub
git push --set-upstream origin backport/backport-9289-to-2.x
# Go back to the original working tree
popd
# Delete the working tree
git worktree remove ../.worktrees/OpenSearch/backport-2.x Then, create a pull request where the |
Signed-off-by: Vikas Bansal <vikasvb90@users.noreply.github.com> (cherry picked from commit 63ce832)
This change is pulling in bouncy castle libraries which are causing havoc with the Security plugins use of SecurityManager. Can we revert the change to |
@peternied We had a discussion here and have been having discussions earlier around the design of encryption and how we want to place it. I believe by |
@vikasvb90 the BC (Bouncycastle) provider is added to core but it is not loaded anywhere (programmatically at least, since modifying the JVM security properties is out of scope), are there any plans to have it added to the list of security providers? ( |
Signed-off-by: Vikas Bansal <vikasvb90@users.noreply.github.com> Signed-off-by: Kaushal Kumar <ravi.kaushal97@gmail.com>
Signed-off-by: Vikas Bansal <vikasvb90@users.noreply.github.com> Signed-off-by: Ivan Brusic <ivan.brusic@flocksafety.com>
Signed-off-by: Vikas Bansal <vikasvb90@users.noreply.github.com> Signed-off-by: Shivansh Arora <hishiv@amazon.com>
Description
This PR adds an encrypted layer on top of a repository which allows encryption to remain transparent to features using a repository.
Related Issues
Meta Issue : #7229
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.