Skip to content

Onboards to centralized resource access control mechanism for ml-model-group #3715

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 16 commits into
base: main
Choose a base branch
from

Conversation

DarshitChanpura
Copy link
Member

Description

Implements resource-access-control for ML-Model-Group.
Feature Proposal: opensearch-project/security#4500

Related Issues

TBD

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@dhrubo-os
Copy link
Collaborator

Apply spotless: ./gradlew spotlessApply

Signed-off-by: Darshit Chanpura <[email protected]>
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 15:57 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 15:57 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 15:57 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 15:57 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 17:15 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 17:15 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 17:15 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 8, 2025 17:15 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 10, 2025 21:17 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 10, 2025 21:17 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 10, 2025 21:17 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 10, 2025 21:17 — with GitHub Actions Failure
Signed-off-by: Darshit Chanpura <[email protected]>
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 14, 2025 21:27 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 14, 2025 21:27 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 14, 2025 21:27 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 14, 2025 21:27 — with GitHub Actions Error
@dhrubo-os
Copy link
Collaborator

Integ tests are failing.

@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 15, 2025 18:11 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 15, 2025 18:11 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 15, 2025 18:11 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 15, 2025 18:11 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura force-pushed the intro-resource-permissions branch from bd13cc6 to b5f7efe Compare April 15, 2025 18:23
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval April 15, 2025 18:24 — with GitHub Actions Waiting
@DarshitChanpura DarshitChanpura requested a deployment to ml-commons-cicd-env-require-approval April 15, 2025 18:24 — with GitHub Actions Waiting
@dhrubo-os
Copy link
Collaborator

can you please rebase with upstream and resolve the conflicts too?

@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 03:52 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 03:52 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 03:52 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 03:52 — with GitHub Actions Failure
@DarshitChanpura
Copy link
Member Author

@dhrubo-os Can you trigger CI please?

Signed-off-by: Darshit Chanpura <[email protected]>
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 22:08 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 22:08 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 22:08 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 26, 2025 22:08 — with GitHub Actions Error
Signed-off-by: Darshit Chanpura <[email protected]>
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 28, 2025 18:09 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 28, 2025 18:09 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 28, 2025 18:09 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 28, 2025 18:09 — with GitHub Actions Failure
Signed-off-by: Darshit Chanpura <[email protected]>
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 29, 2025 01:17 — with GitHub Actions Failure
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 29, 2025 01:17 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 29, 2025 01:17 — with GitHub Actions Error
@DarshitChanpura DarshitChanpura had a problem deploying to ml-commons-cicd-env-require-approval April 29, 2025 01:17 — with GitHub Actions Failure
}
// For backwards compatibility we still allow storing backend_roles data in ml_model_group
// index
updateModelGroup(modelGroupId, r.source(), updateModelGroupInput, wrappedListener, user);
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So if user wants to update resource sharing fields through update model group API, how do we allow it?

@dhrubo-os dhrubo-os had a problem deploying to ml-commons-cicd-env-require-approval May 7, 2025 19:04 — with GitHub Actions Error
@dhrubo-os dhrubo-os had a problem deploying to ml-commons-cicd-env-require-approval May 7, 2025 19:04 — with GitHub Actions Failure
@dhrubo-os dhrubo-os had a problem deploying to ml-commons-cicd-env-require-approval May 7, 2025 19:04 — with GitHub Actions Error
@dhrubo-os dhrubo-os had a problem deploying to ml-commons-cicd-env-require-approval May 7, 2025 19:04 — with GitHub Actions Failure
.getResourceSharingClient();

resourceSharingClient
.share(
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once onboarded and ml access framework is deprecated, what happens to the already existing resources with access controls defined by ml-plugin

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants