cloudfoundry / cloudfoundry/community

Bot accounts require clearer definition

Open
#386 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
57
Forks
250
Avg merge
2d 11h
Merged PRs (30d)
11

Description

The TOC has been making room for working groups to add bot accounts in #375, #378, and other PRs, but we haven't clearly defined what constitutes a bot account and how they should be managed. Since these bot accounts have broad write permissions to repos within a working group area or within the entire working group, they are effectively approvers by proxy within the working group. Working groups and their areas also often use them to generate or to transfer release artifacts, so they present an attractive target for supply-chain attacks. Consequently, their definition and access should be handled with an appropriate degree of care.

The TOC and the working groups should agree on guidelines for:

  • What kinds of accounts should and should not be used as bot accounts
  • Which WG members should and should not have access to credentials for the bot account based on its scope in the WG
  • Where credentials for the bot account should be stored to promote inclusive and transparent management within the working group
  • What the process for adding and removing bot accounts should be
  • Whether bot accounts should use 2-factor auth, if possible within the constraints of automation or WG/area joint management

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review this issue alongside the bot-account work in #375 and #378, then identify the TOC and working-group decision process. Done means the listed questions have agreed guidelines covering account use, credential access and storage, account lifecycle, and 2-factor authentication; no implementation files or tests are named.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.