Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

partition related apis require corresponding permissions #212

Open
PowderLi opened this issue Nov 29, 2023 · 0 comments
Open

partition related apis require corresponding permissions #212

PowderLi opened this issue Nov 29, 2023 · 0 comments

Comments

@PowderLi
Copy link
Contributor

PowderLi commented Nov 29, 2023

improve permission verification

    Global Collection Request
  PrivilegeCreateCollection Y   CreateCollectionRequestAlterCollectionRequest
  PrivilegeDropCollection Y   DropCollectionRequest
  PrivilegeDescribeCollection Y   DescribeCollectionRequest
  PrivilegeShowCollections Y   ShowCollectionsRequest
  PrivilegeLoad   Y LoadCollectionRequest, LoadPartitionsRequest
  PrivilegeRelease   Y ReleaseCollectionRequest, ReleasePartitionsRequest
  PrivilegeGetStatistics   Y GetCollectionStatisticsRequest
  PrivilegeCreatePartition   Y CreatePartitionRequest
  PrivilegeDropPartition   Y DropPartitionRequest
  PrivilegeShowPartitions   Y ShowPartitionsRequest
  PrivilegeHasPartition    Y HasPartitionRequest
  PrivilegeGetFlushState    Y GetFlushStateRequest
  None      HasCollectionRequest
sre-ci-robot pushed a commit to milvus-io/milvus that referenced this issue Dec 12, 2023
issue: [milvus-proto
#212](milvus-io/milvus-proto#212)
master pr: #28961

milvus can't use partition related privileges until upgrade
milvus-proto, even if them were added to milvus-proto

Signed-off-by: PowderLi <[email protected]>
sre-ci-robot pushed a commit to milvus-io/milvus that referenced this issue Dec 18, 2023
issue: #28960 [milvus-proto
#212](milvus-io/milvus-proto#212)

add new configuration: builtinRoles
user can define roles in config file: `milvus.yaml`

there is an example:
1. db_ro, only have read privileges, include load
2. db_rw, read and write privileges, include create/drop/rename
collection
3. db_admin, not only read and write privileges, but also user
administration

Signed-off-by: PowderLi <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant