awslabs / awslabs/aws-deployment-framework
Consider preparing integrity protection for ADF resources
- Dominant language
- Python
- Stars
- 699
- Forks
- 235
- Avg merge
- 20h 53m
- Merged PRs (30d)
- 7
Description
We are happy users of ADF for organisational / baseline (partially together with CT) as well as workload setups. One thing that is currently missing is integrity protection (in the form of an SCP) for the ADF _infrastructure_ itself. Would this be interesting for the project as well?
I understand that (depending on the approach taken, specific resources / prefixes / maybe even tags if the coverage allows it) this might might not extend well to baselines being rolled out via `regional` / `global` but protecting the off-the-shelf ADF components would be enough for us initially (since we try to sail underneath the CT conventions for integrity protection for our customisations anyway).
Since #146 was closed - are you interested in a contribution here?
Contributor guide
Research direction
Start by reviewing how ADF deploys its off-the-shelf infrastructure through the regional and global paths, and how existing Control Tower conventions handle integrity protection. Define the supported resources, prefixes, or tags for an SCP-based approach and confirm that the resulting protection covers the intended ADF components.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, python
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100