Skip to content

Commit dde5f47

Browse files
committed
objstore: add experimental encryption wrapper
Signed-off-by: Michael Hoffmann <[email protected]>
1 parent 11ffbc4 commit dde5f47

File tree

6 files changed

+149
-7
lines changed

6 files changed

+149
-7
lines changed

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ NOTE: As semantic versioning states all 0.y.z releases can contain breaking chan
99
We use *breaking :warning:* to mark changes that are not backward compatible (relates only to v0.y.z releases.)
1010

1111
## Unreleased
12+
- [#46](https://github.com/thanos-io/objstore/pull/46) Objstore: Add experimental encryption wrapper
1213

1314
### Fixed
1415
- [#33](https://github.com/thanos-io/objstore/pull/33) Tracing: Add `ContextWithTracer()` to inject the tracer into the context.

client/factory.go

Lines changed: 21 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ import (
1212
"github.com/go-kit/log/level"
1313
"github.com/pkg/errors"
1414
"github.com/prometheus/client_golang/prometheus"
15+
"golang.org/x/crypto/scrypt"
1516
"gopkg.in/yaml.v2"
1617

1718
"github.com/thanos-io/objstore"
@@ -41,9 +42,14 @@ const (
4142
)
4243

4344
type BucketConfig struct {
44-
Type ObjProvider `yaml:"type"`
45-
Config interface{} `yaml:"config"`
46-
Prefix string `yaml:"prefix" default:""`
45+
Type ObjProvider `yaml:"type"`
46+
Config interface{} `yaml:"config"`
47+
Prefix string `yaml:"prefix" default:""`
48+
Encryption *EncryptionConfig `yaml:"encryption"`
49+
}
50+
51+
type EncryptionConfig struct {
52+
SecretKey string `yaml:"secretKey"`
4753
}
4854

4955
// NewBucket initializes and returns new object storage clients.
@@ -87,5 +93,17 @@ func NewBucket(logger log.Logger, confContentYaml []byte, reg prometheus.Registe
8793
return nil, errors.Wrap(err, fmt.Sprintf("create %s client", bucketConf.Type))
8894
}
8995

96+
if bucketConf.Encryption != nil {
97+
// TODO: salt?
98+
key, err := scrypt.Key([]byte(bucketConf.Encryption.SecretKey), nil, 32768, 16, 1, 32)
99+
if err != nil {
100+
return nil, errors.Wrap(err, "unable to create key from secret key")
101+
}
102+
bucket, err = objstore.BucketWithEncryption(bucket, key)
103+
if err != nil {
104+
return nil, errors.Wrap(err, "unable to create encrypted bucket")
105+
}
106+
}
107+
90108
return objstore.NewTracingBucket(objstore.BucketWithMetrics(bucket.Name(), objstore.NewPrefixedBucket(bucket, bucketConf.Prefix), reg)), nil
91109
}

go.mod

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,7 @@ require (
6767
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 // indirect
6868
github.com/minio/md5-simd v1.1.2 // indirect
6969
github.com/minio/sha256-simd v1.0.0 // indirect
70+
github.com/minio/sio v0.3.0 // indirect
7071
github.com/mitchellh/mapstructure v1.4.3 // indirect
7172
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
7273
github.com/modern-go/reflect2 v1.0.2 // indirect
@@ -80,9 +81,9 @@ require (
8081
github.com/sony/gobreaker v0.5.0 // indirect
8182
github.com/stretchr/objx v0.2.0 // indirect
8283
go.opencensus.io v0.23.0 // indirect
83-
golang.org/x/net v0.2.0 // indirect
84-
golang.org/x/sys v0.3.0 // indirect
85-
golang.org/x/text v0.5.0 // indirect
84+
golang.org/x/net v0.6.0 // indirect
85+
golang.org/x/sys v0.5.0 // indirect
86+
golang.org/x/text v0.7.0 // indirect
8687
golang.org/x/time v0.0.0-20220224211638-0e9765cccd65 // indirect
8788
golang.org/x/xerrors v0.0.0-20220411194840-2f41105eb62f // indirect
8889
google.golang.org/appengine v1.6.7 // indirect
@@ -100,5 +101,5 @@ require (
100101
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v0.5.1
101102
github.com/kr/text v0.2.0 // indirect
102103
github.com/satori/go.uuid v1.2.1-0.20181028125025-b2ce2384e17b // indirect
103-
golang.org/x/crypto v0.3.0 // indirect
104+
golang.org/x/crypto v0.6.0 // indirect
104105
)

go.sum

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -307,6 +307,8 @@ github.com/minio/minio-go/v7 v7.0.45 h1:g4IeM9M9pW/Lo8AGGNOjBZYlvmtlE1N5TQEYWXRW
307307
github.com/minio/minio-go/v7 v7.0.45/go.mod h1:nCrRzjoSUQh8hgKKtu3Y708OLvRLtuASMg2/nvmbarw=
308308
github.com/minio/sha256-simd v1.0.0 h1:v1ta+49hkWZyvaKwrQB8elexRqm6Y0aMLjCNsrYxo6g=
309309
github.com/minio/sha256-simd v1.0.0/go.mod h1:OuYzVNI5vcoYIAmbIvHPl3N3jUzVedXbKy5RFepssQM=
310+
github.com/minio/sio v0.3.0 h1:syEFBewzOMOYVzSTFpp1MqpSZk8rUNbz8VIIc+PNzus=
311+
github.com/minio/sio v0.3.0/go.mod h1:8b0yPp2avGThviy/+OCJBI6OMpvxoUuiLvE6F1lebhw=
310312
github.com/mitchellh/mapstructure v1.4.3 h1:OVowDSCllw/YjdLkam3/sm7wEtOy59d8ndGgCcyj8cs=
311313
github.com/mitchellh/mapstructure v1.4.3/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
312314
github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
@@ -407,11 +409,14 @@ go.uber.org/atomic v1.9.0/go.mod h1:fEN4uk6kAWBTFdckzkM89CLk9XfWZrxpCo0nPH17wJc=
407409
golang.org/x/crypto v0.0.0-20180904163835-0709b304e793/go.mod h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4=
408410
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
409411
golang.org/x/crypto v0.0.0-20190510104115-cbcb75029529/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
412+
golang.org/x/crypto v0.0.0-20190513172903-22d7a77e9e5f/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
410413
golang.org/x/crypto v0.0.0-20190605123033-f99c8df09eb5/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
411414
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
412415
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
413416
golang.org/x/crypto v0.3.0 h1:a06MkbcxBrEFc0w0QIZWXrH/9cCX6KJyWbBOIwAn+7A=
414417
golang.org/x/crypto v0.3.0/go.mod h1:hebNnKkNXi2UzZN1eVRvBB7co0a+JxK6XbPiWVs/3J4=
418+
golang.org/x/crypto v0.6.0 h1:qfktjS5LUO+fFKeJXZ+ikTRijMmljikvG68fpMMruSc=
419+
golang.org/x/crypto v0.6.0/go.mod h1:OFC/31mSvZgRz0V1QTNCzfAI1aIRzbiufJtkMIlEp58=
415420
golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
416421
golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
417422
golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8=
@@ -492,6 +497,8 @@ golang.org/x/net v0.0.0-20220412020605-290c469a71a5/go.mod h1:CfG3xpIq0wQ8r1q4Su
492497
golang.org/x/net v0.0.0-20220425223048-2871e0cb64e4/go.mod h1:CfG3xpIq0wQ8r1q4Su4UZFWDARRcnwPjda9FqA0JpMk=
493498
golang.org/x/net v0.2.0 h1:sZfSu1wtKLGlWI4ZZayP0ck9Y73K1ynO6gqzTdBVdPU=
494499
golang.org/x/net v0.2.0/go.mod h1:KqCZLdyyvdV855qA2rE3GC2aiw5xGR5TEjj8smXukLY=
500+
golang.org/x/net v0.6.0 h1:L4ZwwTvKW9gr0ZMS1yrHD9GZhIuVjOBBnaKH+SPQK0Q=
501+
golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs=
495502
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=
496503
golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
497504
golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
@@ -594,6 +601,8 @@ golang.org/x/sys v0.0.0-20220704084225-05e143d24a9e/go.mod h1:oPkhp1MJrh7nUepCBc
594601
golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
595602
golang.org/x/sys v0.3.0 h1:w8ZOecv6NaNa/zC8944JTU3vz4u6Lagfk4RPQxv92NQ=
596603
golang.org/x/sys v0.3.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
604+
golang.org/x/sys v0.5.0 h1:MUK/U/4lj1t1oPg0HfuXDN/Z1wv31ZJ/YcPiGccS4DU=
605+
golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
597606
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
598607
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
599608
golang.org/x/text v0.0.0-20170915032832-14c0d48ead0c/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
@@ -607,6 +616,8 @@ golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
607616
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
608617
golang.org/x/text v0.5.0 h1:OLmvp0KP+FVG99Ct/qFiL/Fhk4zp4QQnZ7b2U+5piUM=
609618
golang.org/x/text v0.5.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
619+
golang.org/x/text v0.7.0 h1:4BRB4x83lYWy72KwLD/qYDuTu7q9PjSagHvijDw7cLo=
620+
golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
610621
golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
611622
golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
612623
golang.org/x/time v0.0.0-20191024005414-555d28b269f0/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=

objstore.go

Lines changed: 77 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ import (
1818
"github.com/efficientgo/core/logerrcapture"
1919
"github.com/go-kit/log"
2020
"github.com/go-kit/log/level"
21+
"github.com/minio/sio"
2122
"github.com/pkg/errors"
2223
"github.com/prometheus/client_golang/prometheus"
2324
"github.com/prometheus/client_golang/prometheus/promauto"
@@ -395,6 +396,82 @@ func DownloadDir(ctx context.Context, logger log.Logger, bkt BucketReader, origi
395396
// IsOpFailureExpectedFunc allows to mark certain errors as expected, so they will not increment thanos_objstore_bucket_operation_failures_total metric.
396397
type IsOpFailureExpectedFunc func(error) bool
397398

399+
// BucketWithEncryption takes a bucket and transparently encrypts and decrypts its payloads. Its 'Attributes'
400+
// method is ill-defined and will error. It should not be used if the 'Attributes' method is important.
401+
func BucketWithEncryption(b Bucket, key []byte) (*encryptedBucket, error) {
402+
return &encryptedBucket{Bucket: b, cfg: sio.Config{Key: key}}, nil
403+
}
404+
405+
type encryptedBucket struct {
406+
Bucket
407+
408+
cfg sio.Config
409+
}
410+
411+
var errNotExistsSentinel = errors.New("does not exist")
412+
413+
func (eb *encryptedBucket) Attributes(ctx context.Context, name string) (ObjectAttributes, error) {
414+
attrs, err := eb.Bucket.Attributes(ctx, name)
415+
if err != nil {
416+
return attrs, err
417+
}
418+
419+
decSize, err := sio.DecryptedSize(uint64(attrs.Size))
420+
if err != nil {
421+
return ObjectAttributes{}, errors.Wrap(err, "unable to determine unecrypted size")
422+
}
423+
424+
// TODO: check that conversion to int64 is safe?
425+
return ObjectAttributes{Size: int64(decSize), LastModified: attrs.LastModified}, nil
426+
}
427+
428+
func (eb *encryptedBucket) Upload(ctx context.Context, name string, r io.Reader) error {
429+
er, err := sio.EncryptReader(r, eb.cfg)
430+
if err != nil {
431+
return errors.Wrap(err, "unable to create encryption stream")
432+
}
433+
return eb.Bucket.Upload(ctx, name, er)
434+
}
435+
436+
func (eb *encryptedBucket) Get(ctx context.Context, name string) (io.ReadCloser, error) {
437+
return eb.GetRange(ctx, name, 0, -1)
438+
}
439+
440+
func (eb *encryptedBucket) IsObjNotFoundErr(err error) bool {
441+
return errors.Cause(err) == errNotExistsSentinel || eb.Bucket.IsObjNotFoundErr(err)
442+
}
443+
444+
func (eb *encryptedBucket) GetRange(ctx context.Context, name string, off, length int64) (io.ReadCloser, error) {
445+
if exists, err := eb.Bucket.Exists(ctx, name); err != nil {
446+
return nil, err
447+
} else if !exists {
448+
return nil, errNotExistsSentinel
449+
}
450+
451+
br := &bucketReaderAt{ctx: ctx, name: name, b: eb.Bucket}
452+
dr, err := sio.DecryptReaderAt(br, eb.cfg)
453+
if err != nil {
454+
return nil, errors.Wrap(err, "unable to create decryption stream")
455+
}
456+
return io.NopCloser(io.NewSectionReader(dr, off, length)), nil
457+
}
458+
459+
type bucketReaderAt struct {
460+
ctx context.Context
461+
name string
462+
b BucketReader
463+
}
464+
465+
func (br *bucketReaderAt) ReadAt(p []byte, off int64) (n int, err error) {
466+
rc, err := br.b.GetRange(br.ctx, br.name, off, int64(len(p)))
467+
if err != nil {
468+
return 0, err
469+
}
470+
defer rc.Close()
471+
472+
return rc.Read(p)
473+
}
474+
398475
var _ InstrumentedBucket = &metricBucket{}
399476

400477
// BucketWithMetrics takes a bucket and registers metrics with the given registry for

objstore_test.go

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ package objstore
66
import (
77
"bytes"
88
"context"
9+
"encoding/hex"
910
"io"
1011
"os"
1112
"strings"
@@ -204,3 +205,36 @@ func (b unreliableBucket) Get(ctx context.Context, name string) (io.ReadCloser,
204205
}
205206
return b.Bucket.Get(ctx, name)
206207
}
208+
209+
func TestEncryptedBucket(t *testing.T) {
210+
key, _ := hex.DecodeString("6368616e6765207468697320706173736368616e676520746869732070617373")
211+
212+
eb, err := BucketWithEncryption(NewInMemBucket(), key)
213+
testutil.Ok(t, err)
214+
215+
testutil.Ok(t, eb.Upload(context.Background(), "dir/obj1", bytes.NewReader([]byte("foo bar baz"))))
216+
217+
r, err := eb.Get(context.Background(), "dir/obj1")
218+
testutil.Ok(t, err)
219+
220+
content, err := io.ReadAll(r)
221+
testutil.Ok(t, err)
222+
testutil.Equals(t, string(content), "foo bar baz")
223+
224+
r, err = eb.GetRange(context.Background(), "dir/obj1", 4, 3)
225+
testutil.Ok(t, err)
226+
227+
content, err = io.ReadAll(r)
228+
testutil.Ok(t, err)
229+
testutil.Equals(t, string(content), "bar")
230+
231+
r, err = eb.GetRange(context.Background(), "dir/obj1", 8, 3)
232+
testutil.Ok(t, err)
233+
234+
content, err = io.ReadAll(r)
235+
testutil.Ok(t, err)
236+
testutil.Equals(t, string(content), "baz")
237+
238+
_, err = eb.GetRange(context.Background(), "dir/nonexistent", 0, -1)
239+
testutil.Equals(t, eb.IsObjNotFoundErr(err), true)
240+
}

0 commit comments

Comments
 (0)