LTS service accounts
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 65/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- gitlab
- Domain
- ci-cd, devops, documentation, security
Research direction
Start by reviewing the devops-docs repository and the LTS service-account requirements in this issue. Document how to create the key pair, configure zero storage, identify the owner, apply the listed limitations and least-privilege practices, and complete the unfinished responsibility statement; the work is done when the configuration and safe CI/CD usage guidance are clear.
Written by the indexing model from the issue text.
Description
An LTS service account is a regular account with zero storage allocation, owned by a particular user, for the purposes of CI/CD automation interacting with LTS.
How to configure?
- Create a new access/secret key pair in LTS (a new special allocation type)
- Set storage quota to zero bytes
- Set comment to indicate BlazerID of who owns it
Limitations?
- Zero storage allocation
- Owners must be supervisors (Research Lab Supervisor or Core Director)
- Owners are responsible for granting the service account access to data in LTS via bucket policies, we will not ever grant a service account attached to an existing allocation (i.e., as alternative keys for that allocation)
- Owners are responsible for understanding and implementing
Good practices for use?
- Principle of least privilege: only grant the service account access to the data it needs access to, either using bucket policy scoping, or a separate bucket entirely.
- Principle of least function: only use the service account in repos where it is needed.
- We can talk if you believe you need more than one service account.
- Protect your keys using CI/CD variables (https://docs.gitlab.com/ci/variables/#protect-a-cicd-variable)
- Do not ever use your primary allocation keys as CI/CD variables. If they are compromised, all of your data would be compromised. Only ever use service accounts.
- Dominant language
- Python
- Stars
- 1
- Forks
- 9
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from uabrc/devops-docs
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
uabrc/devops-docs#54 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 65/100
uabrc/devops-docs#48 ·
-
Document procedure for ticket management and closureMay be free again @iam4tune claimed this 53 days ago, and no pull request is open. Open
uabrc/devops-docs#97 · 1 assignee ·
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
uabrc/devops-docs#96 ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
uabrc/devops-docs#91 · 1 comment ·
All issues in uabrc/devops-docs
Similar issues
-
P4: low tooling
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
jeffknupp/association#318 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
petercorke/robotics-toolbox-python#709 ·
Maintainers usually reply within 2 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
MakerYuichi/Aegis-pro#114 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
mpfaffenberger/code_puppy#985 · 2 comments ·
Maintainers usually reply within 1 day