bcgov / bcgov/cloud-pathfinder

[Registry] Streamline IAM User Management

Open
#2,638 0 comments 0 reactions 0 assignees View on GitHub
CSP: AWS Epic
Dominant language
Jinja
Stars
2
Forks
7
PR merge metrics
No merged PRs in 30d

Description

**Describe the Issue**
As a team seeking a more flexible and user-centric approach to IAM user management, we recognize that creating IAM users directly in AWS is not feasible due to the ASEA guardrails. To enable our users to have greater control over IAM user management while ensuring compliance, we propose creating an automation process that creates IAM users on their behalf. Users will be able to request IAM user creation and management through the Project Registry, which will trigger the automation process. Additionally, we will enforce permission boundaries to restrict the maximum permissions that can be assigned to these IAM users.

**Additional Context**
- Once the IAM users have been created in the AWS Accounts users can create and delete (rotate) credentials and apply IAM policies
- Open Questions
- What should the permission boundary be? Use the existing one or should it be more restrictive?
-
**Acceptance Criteria**
- Develop an automated process that creates IAM users based on user requests submitted through the Project Registry.
- Implement a user-friendly front-end interface in the Project Registry that allows users to request IAM user creation, deletion, and management.
- Users should be able to create, view and update and delete their IAM users through the Project Registry
- Provide clear documentation and guidelines on how to use the Project Registry interface for IAM user management and working with permission boundaries.
- All Credentials should be automatically rotated every 3 month at minimum
- Ability for users to force a key rotation through the project registry (in case credentials are leaked)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the Project Registry request flow and the AWS IAM automation requirements described in the issue. Resolve the permission-boundary question and define the user-management and credential-rotation workflows; done means the listed creation, management, deletion, documentation, and rotation criteria are met.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, frontend, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.