make HSM configuration more robust to unintended large billings
维护者通常 1 天内回复
@hellais 已经在做这个了。
开始于 2025年3月14日。
评估
这个 Issue 还没有评估数据。
描述
In January 2025 we forgot the HSM modules running in AWS and as a result incurred in 1.6k USD unexpected fees for CloudHSM and in February 2.2k USD.
Going forward we should put things in place to prevent this. Currently this is all reliant on going through the HSM procedure properly and not skipping the last step:
1. Run the command:
create-hsms.sh
wait for the tokens to be created (this will take several minutes).
2. If it’s the first time you are doing signing, ensure that /home/ubuntu/.hsmcredentials constains the username and password to access the code signing key in the format HSM_PASSWORD=”USERNAME:PASSWORD”
You can now sign exe binaries using:
sign-windows-exe.sh [unsigned.exe] [signed.exe]
3. Once you are done be sure to terminate all the running HSMs using:
delete-hsms.sh
We should evaluate having:
- Monitoring that checks the HSM tokens are not running for more than some amount of time and if so sends us a notification
- Automatically terminate the HSM tokens (running
delete-hsms.sh) after some amount of inactivity
- 主要语言
- HCL
- 星标
- 4
- 派生
- 15
- 平均合并
- 3 天 1 小时
- 30 天内合并 PR
- 9
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
ooni/devops 的其他 Issue
-
难度 3/5 1-2 天 新手友好度 58/100
维护者通常 1 天内回复
-
难度 5/5 一周以上 新手友好度 35/100
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 35/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 48/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 55/100
维护者通常 1 天内回复