NASA-IMPACT / NASA-IMPACT/veda-deploy
Design least permissive deployment role ARN configuration to use for all platform infrastructure deployment
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 0
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Investigate what is required for a successful VEDA deployment for the DEPLOYMENT_ROLE_ARN.
We currently have a largely permissive role we use for deployments. It is better if we can find the set of actions required in a statement policy for an IAM Role for deployments.
Acceptance Criteria
- a test stage from VEDA is used to determine the sufficient set of actions required in a statement policy for an IAM role for our deployments
- testing is communicated to teams
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing DEPLOYMENT_ROLE_ARN through the deployment workflows and reviewing the permissions used by a VEDA test stage. Determine the sufficient IAM statement policy, validate it in the test stage, and communicate the testing results to the teams.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, github-actions
- Domain
- cloud, devops, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100