NASA-IMPACT / NASA-IMPACT/veda-deploy

Design least permissive deployment role ARN configuration to use for all platform infrastructure deployment

Open
#195 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Investigate what is required for a successful VEDA deployment for the DEPLOYMENT_ROLE_ARN.

We currently have a largely permissive role we use for deployments. It is better if we can find the set of actions required in a statement policy for an IAM Role for deployments.

Acceptance Criteria
  • a test stage from VEDA is used to determine the sufficient set of actions required in a statement policy for an IAM role for our deployments
  • testing is communicated to teams

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing DEPLOYMENT_ROLE_ARN through the deployment workflows and reviewing the permissions used by a VEDA test stage. Determine the sufficient IAM statement policy, validate it in the test stage, and communicate the testing results to the teams.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, github-actions
Domain
cloud, devops, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.