


























I think its very important for all the s3 implementations to support AssumeRoleWithWebIdentity. This allows workload identities like SPIFFE/SPIRE, Kubernetes Projected Access Tokens, Github tokens, etc to be used for workload auth and things like Keycloak, Google Auth, Entra, etc to be used for User auth. In 2026 we should not be making up random shared secrets anymore for auth.
Surprisingly few "s3 compatible" implementations support this. Minio and Ceph does. I think seaweedfs does too but haven't tried it. Most of the others I've tried do not.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。