Skip to content

feat(policy): add admin:SetRootAccess for disabling the root credential - #271

Merged
harshavardhana merged 1 commit into
minio:mainfrom
harshavardhana:policy-set-root-access-action
Sep 21, 2026
Merged

harshavardhana merged 1 commit into
minio:mainfrom
harshavardhana:policy-set-root-access-action

Conversation

@harshavardhana

@harshavardhana harshavardhana commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Description

Adds admin:SetRootAccess, and a test covering validity, admin:* matching, and which canned policies allow it.

Motivation

Disabling the root credential is the api root_access config key, so today it is reachable by anyone holding
admin:ConfigUpdate — an action that carries the whole configuration surface with it. This action lets the server
require a second, narrower grant for that one decision on top of ConfigUpdate, so taking root out of service is not
bundled with every other config right.

Not added to a canned policy: iamAdmin and infraAdmin each hold only one half of the pair, so the grant would be
inert there. consoleAdmin picks it up through admin:*.

How to test

go test ./policy/ — TestSetRootAccessAdminAction covers it. Verified by mutation: granting the action to a canned
policy that should not have it fails the test.

Types of changes

New feature (non-breaking). No existing action or policy changes behaviour.

Checklist

  • Tests added
  • go build ./... and go test ./policy/ pass
  • gofumpt clean

The AIStor side that enforces this action is a separate change and lands after a version bump here.

Summary by CodeRabbit

  • New Features
    • Added a supported administrative permission for enabling or disabling root credentials.
    • Root credential management is available to console administrators, while remaining restricted for IAM and infrastructure administrators.

Disabling root is stored as the api root_access config key, so today it is reachable by anyone holding admin:ConfigUpdate -
an action that carries the whole configuration surface with it. This action lets a deployment require a second, narrower
grant for that one decision, on top of ConfigUpdate, so taking root out of service is not bundled with every other config
right.

Not added to a canned policy: iamAdmin and infraAdmin each hold only one half of the pair, so the grant would be inert
there. consoleAdmin picks it up through admin:*.
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 33645fac-605a-40d8-a772-101d674fd481

📥 Commits

Reviewing files that changed from the base of the PR and between 525a565 and 4a58d67.

📒 Files selected for processing (2)
  • policy/admin-action.go
  • policy/admin-action_test.go

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The policy package adds SetRootAccessAdminAction, registers it as supported, and tests its validity, wildcard matching, and permissions in the built-in admin policies.

Changes

Root Access Admin Action

Layer / File(s) Summary
Action definition, registration, and policy validation
policy/admin-action.go, policy/admin-action_test.go
Defines and registers SetRootAccessAdminAction. Tests confirm action validity, admin:* matching, and expected permissions for consoleAdmin, iamAdmin, and infraAdmin.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: klauspost

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding the admin:SetRootAccess action for disabling the root credential.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit finds a root key bright,
Adds its name to the policy list,
Console hops with granted light,
IAM and infra still resist,
Tests applaud with every twist.

Comment @coderabbitai help to get the list of available commands.

@harshavardhana
harshavardhana merged commit f140966 into minio:main Sep 21, 2026
11 checks passed
@harshavardhana
harshavardhana deleted the policy-set-root-access-action branch September 21, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant