Review Security Landscape
- 主要言語
- Shell
- スター
- 3
- フォーク
- 3
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
I'm playing a bit fast and loose IMO to get this up and running. From what I can tell, I'm doing pretty well. However, it would be great to do a good review of the following:
## Public Key Infrastructure
- Should the CA for the auth store be independent of the CA for communicating amongst Docker nodes?
- Should each deployment be a wholly separate entity with a new CA?
## ObjectRocket (or other programmatic Database access)
- In the same spirit of total annihilation, we could be creating access to the main mongo database programmatically with a new user for every deployment.
Side Ansible question - are the values of variables rendered locally or on the host being deployed to?
Clearly flying has made me crazy.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
ファイル、テスト、エントリポイントは指定されていません。まず PKI の分離とデプロイメントごとの CA に関する問題を調査し、次にプログラムによる MongoDB へのアクセス方法と、Ansible が変数をどのようにレンダリングするかを確認してください。セキュリティ上の判断と推奨されるデプロイメント方法が文書化されれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- ansible, docker, mongodb
- 領域
- databases, devops, infrastructure, security
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 15/100