oasisprotocol / oasisprotocol/oasis-core

Annual Review of Cloud Credential Handling, Policies

Open
#1,402 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

epic
Dominant language
Go
Stars
369
Forks
151
Avg merge
1d 3h
Merged PRs (30d)
6

Description

To ensure our security posture does not degrade, we should have annual review of how we handle our cloud credentials, dev token wallet keys, etc.

Details

Periodic reviews -- organization growth / changes, new cloud providers, etc. Primarily this is to ensure that we do not forget.

Not sure if this should be an issue per se, since an annual thing is never resolved.

Acceptance Criteria

  • List of the kinds of credentials/policies to be reviewed
  • Annual reviews scheduled (into the future)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points. Start by identifying where cloud credentials, dev token wallet keys, and related policies are documented, then inventory the credential and policy categories that need review. Done means the review list is documented and recurring annual reviews are scheduled into the future.

Written by the indexing model from the issue text.

Assessment

Domain
cloud, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.