bcgov / bcgov/cloud-pathfinder

AWS Break Glass Account Finalization

Open
#3,054 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jinja
Stars
2
Forks
7
PR merge metrics
No merged PRs in 30d

Description

**Describe the Issue**
Break Glass Account is used for a person to be able to access privileges to certain AWS accounts in exceptional circumstances by using an approved process. Possible use cases including Incident remediation, Forensic Investigation, Disaster Recovery, Kill Switch

**Additional Context**
- Discuss use case w/ Nick, Warren, Max
- Understand current privilege account's console access, programmatic access.
- Design the access to ensure all scenarios covered
- IdP is not available can't use to authorize the access
- No root account access

**Acceptance Criteria**
- [ ] Review
- [ ] Test
- [ ] Documentation

Contributor guide

No contributing guide indexed for this repository

Research direction

No files or tests are named. Start by discussing the listed use cases with Nick, Warren, and Max, then review the current privileged account's console and programmatic access. Define an access design that works without the IdP or root account, and consider the work done when it has been reviewed, tested, and documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
authentication, authorization, cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.