oasisprotocol / oasisprotocol/oasis-core
Annual Review of Cloud Credential Handling, Policies
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 369
- Forks
- 151
- Avg merge
- 1d 3h
- Merged PRs (30d)
- 6
Description
To ensure our security posture does not degrade, we should have annual review of how we handle our cloud credentials, dev token wallet keys, etc.
Details
Periodic reviews -- organization growth / changes, new cloud providers, etc. Primarily this is to ensure that we do not forget.
Not sure if this should be an issue per se, since an annual thing is never resolved.
Acceptance Criteria
- List of the kinds of credentials/policies to be reviewed
- Annual reviews scheduled (into the future)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no files, tests, or entry points. Start by identifying where cloud credentials, dev token wallet keys, and related policies are documented, then inventory the credential and policy categories that need review. Done means the review list is documented and recurring annual reviews are scheduled into the future.
Written by the indexing model from the issue text.
Assessment
- Domain
- cloud, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100