Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OIDC IAM policy for CI/CD Deployments #115

Open
2 tasks
sjoshi-jpl opened this issue Oct 17, 2024 · 8 comments
Open
2 tasks

OIDC IAM policy for CI/CD Deployments #115

sjoshi-jpl opened this issue Oct 17, 2024 · 8 comments

Comments

@sjoshi-jpl
Copy link

sjoshi-jpl commented Oct 17, 2024

💡 Description

Draft a more restrictive OIDC policy for CI/CD deployments in MCP. This is a replacement policy for current MCP OIDC policy in Dev.

Sub-tasks

  • Test policy with registry-api
  • Test policy with s3-browser
@sjoshi-jpl
Copy link
Author

@tloubrieu-jpl @viviant100 I've provided a more restrictive policy to Andrew from SA over Slack. They need to review it and configure it for the OIDC IAM role. If any changes are required, kindly work with Andrew to add/remove permissions.

@sjoshi-jpl
Copy link
Author

Refactor policy provided to SA team with resource blocks

@tloubrieu-jpl
Copy link
Member

Ready for the SA's to deploy.

@tloubrieu-jpl
Copy link
Member

Andrew will setup a call Wednesday on that.

@sjoshi-jpl
Copy link
Author

Sagar to work with Paul from SA team to add prefix conditions instead of tags in OIDC policy.

@tloubrieu-jpl
Copy link
Member

Sagar works on a IAM policy script which uses the prefix of ARN to filter the resources which can be deployed.

@sjoshi-jpl
Copy link
Author

Policy updated as requested by SA team with resource ARNs and prefixes. SA review in progress.

@jordanpadams
Copy link
Member

@sjoshi-jpl added 2 sub-tasks to issue above

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: ToDo
Development

No branches or pull requests

3 participants