chaoss / chaoss/infrastructure

Document the policies surrounding slack integrations

Open
#13 1 comment 0 reactions 0 assignees View on GitHub
documentation
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

- who is allowed access to secrets like bot tokens
- what permissions we grant to bots before we hand that out
- how do we ensure bots are only granted the minimal necessary permissions (to mitigate damage for leaked keys)
- how do we ensure that unused bots are decommissioned?

I personally think maybe treating each bot as a "project" and ensuring we have thorough docs on its specific purpose/owner/decommission plan (similar to what im trying to do for the website in #11) would be a good way to do this (in addition to having general policy rules)

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the repository's existing infrastructure documentation and issue #11 for the expected documentation approach. Cover access to bot secrets, granted permissions, least-privilege checks, and decommissioning unused bots, with each bot's purpose, owner, and decommission plan documented when applicable.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.