Review Security Landscape
- Lingua principale
- Shell
- Stelle
- 3
- Fork
- 3
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
I'm playing a bit fast and loose IMO to get this up and running. From what I can tell, I'm doing pretty well. However, it would be great to do a good review of the following:
## Public Key Infrastructure
- Should the CA for the auth store be independent of the CA for communicating amongst Docker nodes?
- Should each deployment be a wholly separate entity with a new CA?
## ObjectRocket (or other programmatic Database access)
- In the same spirit of total annihilation, we could be creating access to the main mongo database programmatically with a new user for every deployment.
Side Ansible question - are the values of variables rendered locally or on the host being deployed to?
Clearly flying has made me crazy.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Direzione di ricerca
Non sono indicati file, test o punti di ingresso. Inizia analizzando le questioni relative alla separazione della PKI e a una CA per deployment, quindi esamina l'accesso programmatico a MongoDB e il modo in cui Ansible esegue il rendering delle variabili. Il lavoro è completato quando le decisioni di sicurezza e l'approccio di deployment consigliato sono documentati.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- ansible, docker, mongodb
- Ambito
- databases, devops, infrastructure, security
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 15/100