Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support restricted home directory for aws_transfer_user #13794

Closed
cparmar opened this issue Jun 17, 2020 · 2 comments
Closed

Support restricted home directory for aws_transfer_user #13794

cparmar opened this issue Jun 17, 2020 · 2 comments
Labels
enhancement Requests to existing resources that expand the functionality or scope. service/transfer Issues and PRs that pertain to the transfer service.

Comments

@cparmar
Copy link

cparmar commented Jun 17, 2020

Community Note

  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or other comments that do not add relevant new information or questions, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

Description

AWS Transfer Family has an option to restrict a user to their home directory.

For Restricted, select the check box so that your users can't access anything outside of that folder and can't see the Amazon S3 bucket or folder name.

Looking at the AWS CLI and Go SDK docs, there is a home directory type parameter which can be set to PATH or LOGICAL. I believe the provider currently uses PATH whereas the Restricted check box uses LOGICAL and uses the home directory mapping parameter to restrict the access.

Here is the output from the AWS CLI:

aws transfer describe-user --server-id <REDACTED> --user-name cparmar
{
    "ServerId": "<REDACTED>",
    "User": {
        "Arn": "arn:aws:transfer:eu-west-1:<REDACTED>:user/<REDACTED>/cparmar",
        "HomeDirectoryMappings": [
            {
                "Entry": "/",
                "Target": "/<BUCKET NAME>/cparmar"
            }
        ],
        "HomeDirectoryType": "LOGICAL",
        "Role": "arn:aws:iam::<REDACTED>:role/transfer_service-user",
        "SshPublicKeys": [
            {
                "DateImported": "2020-06-17T12:38:40.485000+01:00",
                "SshPublicKeyBody": "<REDACTED>",
                "SshPublicKeyId": "<REDACTED>"
            }
        ],
        "Tags": [],
        "UserName": "cparmar"
    }
}

Support for the restricted check box using the terraform AWS provider.

New or Affected Resource(s)

  • aws_transfer_user

Potential Terraform Configuration

# Copy-paste your Terraform configurations here - for large Terraform configs,
# please use a service like Dropbox and share a link to the ZIP file. For
# security, you can also encrypt the files using our GPG public key.

References

@cparmar cparmar added the enhancement Requests to existing resources that expand the functionality or scope. label Jun 17, 2020
@ghost ghost added the service/transfer Issues and PRs that pertain to the transfer service. label Jun 17, 2020
@github-actions github-actions bot added the needs-triage Waiting for first response or review from a maintainer. label Jun 17, 2020
@ewbankkit
Copy link
Contributor

@cparmar Thanks for raising this issue.
It is a duplicate of #11632. Please upvote that issue and add any additional comments there.

@ghost
Copy link

ghost commented Jul 17, 2020

I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.

If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. Thanks!

@ghost ghost locked and limited conversation to collaborators Jul 17, 2020
@breathingdust breathingdust removed the needs-triage Waiting for first response or review from a maintainer. label Sep 17, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement Requests to existing resources that expand the functionality or scope. service/transfer Issues and PRs that pertain to the transfer service.
Projects
None yet
Development

No branches or pull requests

3 participants