Storage Tiering Service  ·  View 29 of 31  ·  7 · Assurance

Short-Lived Credentials

How a mover gets permission to write into exactly one tier for fifteen minutes, with no stored secret anywhere in the fleet.

Editable source SVG draw.io All views
Mover pod SPIRE agent SPIRE server RGW STS Ceph RGW OpenBao Release gate 1. workload API · attest pod 2. node and pod selectors 3. JWT-SVID · aud rgw · 5 min 4. AssumeRoleWithWebIdentity 5. verify via SPIRE OIDC discovery 6. 15 min · PutObject on cold 7. PUT · SSE-KMS key of tenant 8. wrap data key 9. DELETE source object 10. AccessDenied 11. assume release-warm role 12. 15 min · DeleteObject on warm Short-Lived Credentials — One Tier, One Operation, Fifteen Minutes Nothing in the mover fleet is a long-lived secret. A stolen token is worth at most fifteen minutes of copying into one tier. v 1.0 · owner Security Architecture · date 2026-09

Decisions

  • SPIRE attests the pod and issues a JWT-SVID. RGW's STS trusts SPIRE's OIDC discovery endpoint and exchanges the SVID for credentials bound to one role: PutObject on one tier, or DeleteObject on one tier.
  • Roles are per tier and per operation. There is no role that can both write to cold and delete from warm, so no single token can complete a movement end to end.
  • OpenBao holds tenant keys for RGW server-side encryption. The mover never sees a key, only a key id.

Proof-phase checks

  • RGW AssumeRoleWithWebIdentity accepting SPIRE-issued JWT-SVIDs with the expected audience and subject claims.
  • RGW SSE-KMS against OpenBao's transit engine at mover write rates, and behaviour when OpenBao is briefly unreachable: writes should fail, not fall back to unencrypted.

Numbers

  • SVID lifetime 5 minutes, STS credentials 15 minutes, renewed at two thirds of lifetime.