Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔒 Refactor AP Service Role Policy #4913

Closed
5 tasks
Tracked by #2955
julialawrence opened this issue Aug 7, 2024 · 2 comments
Closed
5 tasks
Tracked by #2955

🔒 Refactor AP Service Role Policy #4913

julialawrence opened this issue Aug 7, 2024 · 2 comments

Comments

@julialawrence
Copy link
Contributor

User Story

Cut down the number of permissions in the analytical platform ui service role so it adheres to the principle of least-privilege.

Value / Purpose

The analytical platform UI service role is currently defined with a number of service:* permissions in its policy. This allows us to speed development of a critical piece of work but is not sound security-wise. Before it goes before users, we want to create a usable but secure role.

Useful Contacts

Michael Collins, Julia Lawrence

User Types

AP Ops

Hypothesis

No response

Proposal

Refactor this policy to only allow enough actions to perform APUI functions and remove blanket service permisions:
https://github.com/ministryofjustice/modernisation-platform-environments/blob/98f36ad5f4a2e501a7df60477d4f2a26cebd696f/terraform/environments/analytical-platform-compute/iam-policies.tf#L208

Additional Information

No response

Definition of Done

  • Role policy refactored
  • Policy tested
  • Policy deployed
  • Another team member has reviewed
  • Tests are green
Copy link
Contributor

github-actions bot commented Oct 7, 2024

This issue is being marked as stale because it has been open for 60 days with no activity. Remove stale label or comment to keep the issue open.

@github-actions github-actions bot added the stale label Oct 7, 2024
Copy link
Contributor

This issue is being closed because it has been open for a further 7 days with no activity. If this is still a valid issue, please reopen it, Thank you!

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Oct 15, 2024
@github-project-automation github-project-automation bot moved this from 👀 TODO to 🎉 Done in Analytical Platform Oct 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Archived in project
Development

No branches or pull requests

1 participant