ooni / ooni/devops

Tighten permissions of the OONIDevopsPolicy AWS policy

Open
#247 0 comments 0 reactions 1 assignee View on GitHub

@LDiazN is already working on this.

Since Jul 2, 2025.

funder/otffoss2025 security
Dominant language
HCL
Stars
4
Forks
15
Avg merge
1h 50m
Merged PRs (30d)
4

Description

The OONIDevopsPolicy could be a bit more narrowly scoped (https://github.com/ooni/devops/blob/c41f0d1cbc45170708985cddc0eaed01f2fafd9b/tf/modules/adm_iam_roles/main.tf#L12).

We should look into what's the minimal set of permissions necessary to allow it to perform the necessary terraform operations and limit its scope to only those.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.