chaoss / chaoss/infrastructure
Document the policies surrounding slack integrations
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
- who is allowed access to secrets like bot tokens
- what permissions we grant to bots before we hand that out
- how do we ensure bots are only granted the minimal necessary permissions (to mitigate damage for leaked keys)
- how do we ensure that unused bots are decommissioned?
I personally think maybe treating each bot as a "project" and ensuring we have thorough docs on its specific purpose/owner/decommission plan (similar to what im trying to do for the website in #11) would be a good way to do this (in addition to having general policy rules)
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the repository's existing infrastructure documentation and issue #11 for the expected documentation approach. Cover access to bot secrets, granted permissions, least-privilege checks, and decommissioning unused bots, with each bot's purpose, owner, and decommission plan documented when applicable.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100