Restrict bucket owner Cloud Object Storage API operations

In Container Mode, by default, the user with bucket "full_control" permission can use S3 to retrieve security information (such as ACL or CORS) or create or delete a bucket.

In Vault Mode, the Provisioning API provides flexibility for a service provider to have full control for all buckets. Similarly, in Container Mode, the system allows a user to configure through the Manager Web interface or Manager REST API whether an end user can perform operations that are only allowed for those with the "full_control" permission.

A System administrator can restrict an End-User to not allow some bucket-level S3 operations, by selecting a checkbox on container mode configuration to allow create, delete, configure bucket operations only via service API.

It can be applied to all access pools or customized for each access pool. When set to false on the manager UI or API, the user from all access pools with the bucket "full_control" permission cannot use S3 to retrieve security information, such as ACL or CORS on a bucket or create/delete a bucket, and can only perform operations allowed for users with read/write permission. If the “full_control” permission is needed for some users to perform the S3 operation in some vaults, the System Admin needs to deploy these vaults into a separate access pool and contact IBM support to enable these bucket-level S3 operations on this access pool for the end users.

Table 1. Allowed S3 operations
Standard Vault Converted to container Mode Restricted S3 operation mode
Permission Supported S3 bucket Operation Permission Supported S3 bucket operation Supported S3 bucket Operation
Read/Write (1st writer and no owner for the bucket) HEAD bucket Owner(full control) Complete bucket-level S3 Operation set HEAD bucket
Read/Write (Other users) HEAD bucket Read/Write HEAD bucket HEAD bucket
Owner (full_control) Complete bucket-level S3 Operation Set Owner (full_control)

Complete bucket-level S3 Operation Set

HEAD bucket