From c703ef5f384b485b4b3d1c66a3129eb108494605 Mon Sep 17 00:00:00 2001 From: Patrick Donnelly Date: Thu, 18 Jun 2020 10:00:05 -0700 Subject: [PATCH] cephadm: restrict mds caps to cephfs pools Fixes: https://tracker.ceph.com/issues/46081 Signed-off-by: Patrick Donnelly (cherry picked from commit 1ef958085d1fa86f3c79ba25b0e20be2e6fc5dd5) --- src/pybind/mgr/cephadm/services/cephadmservice.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/pybind/mgr/cephadm/services/cephadmservice.py b/src/pybind/mgr/cephadm/services/cephadmservice.py index c5ff300be5033..d66b3df83eaf9 100644 --- a/src/pybind/mgr/cephadm/services/cephadmservice.py +++ b/src/pybind/mgr/cephadm/services/cephadmservice.py @@ -188,7 +188,7 @@ class MdsService(CephadmService): 'prefix': 'auth get-or-create', 'entity': 'mds.' + mds_id, 'caps': ['mon', 'profile mds', - 'osd', 'allow rwx', + 'osd', 'allow rw tag cephfs *=*', 'mds', 'allow'], }) return self.mgr._create_daemon('mds', mds_id, host, keyring=keyring) -- 2.39.5