cloudfoundry / cloudfoundry/community
Bot accounts require clearer definition
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 57
- Forks
- 250
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 11
Description
The TOC has been making room for working groups to add bot accounts in #375, #378, and other PRs, but we haven't clearly defined what constitutes a bot account and how they should be managed. Since these bot accounts have broad write permissions to repos within a working group area or within the entire working group, they are effectively approvers by proxy within the working group. Working groups and their areas also often use them to generate or to transfer release artifacts, so they present an attractive target for supply-chain attacks. Consequently, their definition and access should be handled with an appropriate degree of care.
The TOC and the working groups should agree on guidelines for:
- What kinds of accounts should and should not be used as bot accounts
- Which WG members should and should not have access to credentials for the bot account based on its scope in the WG
- Where credentials for the bot account should be stored to promote inclusive and transparent management within the working group
- What the process for adding and removing bot accounts should be
- Whether bot accounts should use 2-factor auth, if possible within the constraints of automation or WG/area joint management
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review this issue alongside the bot-account work in #375 and #378, then identify the TOC and working-group decision process. Done means the listed questions have agreed guidelines covering account use, credential access and storage, account lifecycle, and 2-factor authentication; no implementation files or tests are named.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100