← ClaudeAtlas

ceph-s3listed

Run Ceph RGW as an S3 endpoint under Rook (CephObjectStore, CephObjectStoreUser, ObjectBucketClaim, COSI, CephBucketTopic, multisite realms/zones). Core knowledge: the 19.2.6 / 20.2.4 RGW security fixes and their fallout (SigV4 hardening rejecting presigned PUTs and RGW's own multisite forwarding; rgw_sigv4_insecure + rgw_s3_client_max_sig_ver), AWS SDK default checksums vs RGW (CRC64NVME only in Tentacle), bucket index sharding and large-omap warnings, Tentacle's two-phase reshard, RGW accounts (CephObjectStoreAccount, experimental), and Tentacle S3 behaviour changes (LastModified truncation, tenant IAM deprecation).
air-gapped/skills · ★ 5 · AI & Automation · score 80
Install: claude install-skill air-gapped/skills
# ceph-s3 Defaults read from `src/common/options/rgw.yaml.in` at v19.2.6 and v20.2.4; Rook docs at v1.20.7 and master; tracker and ceph-users as cited. Verified **2026-09-23**. ## 19.2.6 / 20.2.4 RGW security fixes and their fallout | CVE | What | Fixed | |---|---|---| | CVE-2026-54330 | SigV4 did not check that added `x-amz-*` headers on a presigned request were signed | 19.2.6, 20.2.4 | | CVE-2026-39944 | STS session-token fields (`is_admin`, account type) could be bit-flipped → RGW admin | 19.2.6, 20.2.4 | | CVE-2025-30156 | CephX (cluster-wide, not RGW-only) — see rook-ceph-best-practices | 19.2.6, 20.2.4 | The SigV4 fix breaks two things: 1. **Presigned PUTs from some clients** (restic, PHP SDKs) that send an unsigned `Content-Type` — rejected (tracker 79674). Workaround: `ceph config set client.rgw rgw_sigv4_insecure true`, until 19.2.7 / 20.2.5. 2. **RGW multisite forwarding** (non-master zone → master, e.g. bucket create): `403 AccessDenied` even with every cluster patched (tracker 79698). `rgw_sigv4_insecure` alone does **not** fix it. Set both `rgw_sigv4_insecure: "true"` and `rgw_s3_client_max_sig_ver: "2"` in every zone **before** upgrading. Under Rook, put them in the CephObjectStore `gateway` config or `rook-config-override`. Both workarounds re-open CVE-2026-54330: scope them to the affected clients/zones and revert (`"false"` / `"-1"`) once everything runs a fixed release. ## AWS SDK checksums AWS SDKs released from early 2025 s