Research 015: reopen the comparison — the premise for narrowing to one candidate was false
SeaweedFS was scoped as primary because it looked like the only candidate preserving OIDC console login. Measured: its admin UI is Apache-2.0 but its identity-provider integration is not — console SSO sits behind the per-TB commercial licence, alongside point-in-time recovery and automatic EC repair. The free build gives OIDC on the S3 API via STS and a console authenticated by local username and password. So the answer to the gating question is that no candidate preserves the current feature set for free, which this effort had written down as a possible outcome. Reopened across three candidates with the requirement-by-requirement evidence in 01. Two corrections to what the overview recorded. RustFS is not a binary-level drop-in retaining existing data: API and on-disk compatibility are separate paths and the on-disk one is preview-scoped. And it carries an open defect in the credential path the bucket provision depends on, which gates it specifically. Nothing graduates before two measurements named in 01: whether an authenticating proxy is an acceptable answer to console SSO, and which S3 endpoints consumers actually call — the latter because Garage does not implement the full span and cannot be ranked until that is counted.
This commit is contained in:
@@ -64,27 +64,33 @@ OIDC story, not spread across the catalogue.
|
||||
|
||||
## Candidates
|
||||
|
||||
Scoped to **SeaweedFS** as the primary, with the others recorded so the rejection is not
|
||||
rediscovered.
|
||||
**The comparison is open across three candidates.** It was briefly narrowed to SeaweedFS; that
|
||||
narrowing did not survive measurement and was reopened on 2026-09-24. The evidence, the full
|
||||
requirement-by-requirement table and what each option costs are in
|
||||
[01 — the candidates measured](01-candidate-comparison.md).
|
||||
|
||||
- **SeaweedFS** — Apache-2.0, Go, twelve-plus years of development, erasure coding, and OIDC
|
||||
support in its S3/STS layer. Chosen to scope because it is the only candidate that plausibly
|
||||
preserves the OIDC requirement above, which is the one requirement that is live and least
|
||||
substitutable.
|
||||
- **Garage** — the lightest to operate and the simplest model, but **no native identity-provider
|
||||
integration**. Adopting it means losing OIDC console login or fronting it with a proxy. A real
|
||||
functional regression against something currently in use.
|
||||
- **RustFS** — markets itself as a binary-level drop-in retaining existing data, buckets and
|
||||
configuration, which would make the data migration close to trivial. Young, and that claim is
|
||||
exactly the kind that must be verified on a copy before it is believed.
|
||||
- **Ceph RGW** — the most capable and the most operationally expensive; disproportionate to a mesh
|
||||
where the object store is an ordinary module, not a platform.
|
||||
In short, and only in short:
|
||||
|
||||
**The first thing to verify, because the choice turns on it:** how much of SeaweedFS's OIDC story
|
||||
is in the freely licensed build, and whether its shape — IAM/STS token exchange — can actually
|
||||
stand in for a console that redirects a human to an identity provider. If it cannot, the honest
|
||||
finding may be that **no** candidate preserves the current feature set, and the decision becomes
|
||||
which regression to accept. That question is worth answering before any migration work starts.
|
||||
- **SeaweedFS** — Apache-2.0, the longest field record, erasure coding. Its **console OIDC is an
|
||||
Enterprise feature**; the free build authenticates the console with a local username and
|
||||
password. This is what falsified the original narrowing.
|
||||
- **Garage** — the best match for how the mesh provisions, with a first-class admin REST API
|
||||
scoped to exactly bucket and key creation. Costs: replication rather than erasure coding, no
|
||||
full S3 endpoint span, and neither console nor identity integration.
|
||||
- **RustFS** — the only candidate preserving the live behaviour, with a MinIO-shaped console and
|
||||
documented OIDC against Keycloak, under Apache-2.0. Costs: it reached GA eight days before this
|
||||
was written, and an open defect is reported in the credential path the mesh's bucket provision
|
||||
depends on.
|
||||
- **Ceph RGW** — remains rejected as disproportionate where the object store is an ordinary
|
||||
module rather than a platform.
|
||||
|
||||
**The question that decided the original narrowing has been answered** — SeaweedFS's console OIDC
|
||||
is not in the free build — and the answer was *"no candidate preserves the current feature set
|
||||
for free"*, exactly the outcome this effort said was possible. The decision is therefore not
|
||||
which product is best in the abstract but **which cost is acceptable**, and two measurements
|
||||
gate it: whether an authenticating proxy is an acceptable answer to console single sign-on, and
|
||||
which S3 endpoints consumers actually call. Both are named in
|
||||
[01](01-candidate-comparison.md#what-is-still-unmeasured). Nothing graduates before them.
|
||||
|
||||
## The migration track, in outline
|
||||
|
||||
|
||||
Reference in New Issue
Block a user