awslabs / awslabs/aws-deployment-framework

Consider preparing integrity protection for ADF resources

Open
#206 5 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
699
Forks
235
Avg merge
20h 53m
Merged PRs (30d)
7

Description

We are happy users of ADF for organisational / baseline (partially together with CT) as well as workload setups. One thing that is currently missing is integrity protection (in the form of an SCP) for the ADF _infrastructure_ itself. Would this be interesting for the project as well?

I understand that (depending on the approach taken, specific resources / prefixes / maybe even tags if the coverage allows it) this might might not extend well to baselines being rolled out via `regional` / `global` but protecting the off-the-shelf ADF components would be enough for us initially (since we try to sail underneath the CT conventions for integrity protection for our customisations anyway).

Since #146 was closed - are you interested in a contribution here?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing how ADF deploys its off-the-shelf infrastructure through the regional and global paths, and how existing Control Tower conventions handle integrity protection. Define the supported resources, prefixes, or tags for an SCP-based approach and confirm that the resulting protection covers the intended ADF components.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.