Role-based data access
Role-based data access, including: assigning, to a storage volume of a storage system, a volume-level access policy; and determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access, including allowing the access responsive to the one or more attributes meeting the volume-level access policy or denying the access responsive to the one or more attributes failing to meet the volume-level access policy.
1. A method implemented by a computing device that includes a processor, the method comprising:
assigning, to a storage volume of a storage system, a volume-level access policy, the storage volume storing a plurality of data objects, wherein assigning the volume-level access policy to the storage volume restricts access to each data object of the plurality of the data objects stored by the storage volume, and wherein the restriction is based on a role of an entity requesting access to any data object of the plurality of data objects stored by the storage volume; and
determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access.
2. The method of claim 1 , wherein determining whether to allow access to the storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.
3. The method of claim 1 , wherein determining whether to allow access to the storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.
4. The method of claim 1 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.
5. The method of claim 1 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.
6. The method of claim 1 , wherein the volume-level access policy indicates one or more allowable storage operations and the one or more attributes comprise a type of storage operation of the request.
7. The method of claim 1 , further comprising:
receiving a request to modify the volume-level access policy to an updated volume-level access policy; and
allowing the request responsive to the updated volume-level access policy being more restrictive than the volume-level access policy.
8. The method of claim 1 , further comprising:
receiving a request to modify the volume-level access policy to an updated volume-level access policy; and
denying the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.
9. An apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:
assigning, to a storage volume of a storage system, a volume-level access policy, the storage volume storing a plurality of data objects, wherein assigning the volume-level access policy to the storage volume restricts access to each data object of the plurality of the data objects stored by the storage volume, and wherein the restriction is based on a role of an entity requesting access to any data object of the plurality of data objects stored by the storage volume; and
determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access.
10. The apparatus of claim 9 , wherein determining whether to allow access to the storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.
11. The apparatus of claim 9 , wherein determining whether to allow access to the storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.
12. The apparatus of claim 9 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.
13. The apparatus of claim 9 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.
14. The apparatus of claim 9 , wherein the volume-level access policy indicates one or more allowable storage operations and the one or more attributes comprise a type of storage operation of the request.
15. The apparatus of claim 9 , wherein the steps further comprise:
receiving a request to modify the volume-level access policy to an updated volume-level access policy; and
allowing the request responsive to the updated volume-level access policy being more restrictive than the volume-level access policy.
16. The apparatus of claim 9 , wherein the steps further comprise:
receiving a request to modify the volume-level access policy to an updated volume-level access policy; and
denying the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.
17. A computer program product disposed upon a computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:
assigning, to a storage volume of a storage system, a volume-level access policy, the storage volume storing a plurality of data objects, wherein assigning the volume-level access policy to the storage volume restricts access to each data object of the plurality of the data objects stored by the storage volume, and wherein the restriction is based on a role of an entity requesting access to any data object of the plurality of data objects stored by the storage volume; and
determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access.
18. The computer program product of claim 17 , wherein determining whether to allow access to the storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.
19. The computer program product of claim 17 , wherein determining whether to allow access to the storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.
20. The computer program product of claim 17 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.