Altinn / altinn-platform

Altinn Platform infrastructure
6 stars 1 forks source link

Reconstructing IAC and Azure structure for Authorization #622

Open SandGrainOne opened 6 months ago

SandGrainOne commented 6 months ago

Reason: Altinn-Authorization component should be written out and installed seperatly from the Altinn-platform component. This will make both changes, security and upgrades less challenging.

Pre-refinement suggestions:

 - Create their own pipelines
          - Should GitHub be considered)
          - ,
 - Make IAC independent from the Platform IAC
          - Choice of code language
          - Could IAC be parten more than one Script
Move out all Authorization infrastructure to new subscriptions:
- Storage
- Auditlog
- PostgreDB(er)
- Accessmanagement 
- Kubernetes cluster (Running in the platform AKS now, so their own will increase cost)
             - Benytte anledningen til utføre en overgang til Container Apps
- Authentication Frontend
- FunctionApps
- AppInsights
- Keyvault(s)
### Tasks
- [ ] https://github.com/Altinn/altinn-platform/issues/635
- [ ] https://github.com/Altinn/altinn-platform/issues/637
- [ ] https://github.com/Altinn/altinn-platform/issues/650
- [ ] https://github.com/Altinn/altinn-platform/issues/642
- [ ] https://github.com/Altinn/altinn-platform/issues/638
- [ ] https://github.com/Altinn/altinn-platform/issues/644
- [ ] https://github.com/Altinn/altinn-platform/issues/646
- [ ] https://github.com/Altinn/altinn-platform/issues/645
- [ ] https://github.com/Altinn/altinn-platform/issues/643
- [ ] https://github.com/Altinn/altinn-platform/issues/640
- [ ] https://github.com/Altinn/altinn-platform/issues/641
- [ ] https://github.com/Altinn/altinn-platform/issues/639
jonkjetiloye commented 6 months ago

@SandGrainOne Her trenger vi vel ett oppstartsmøte hvor vi får diskutert hva vi ønsker å oppnå og hvordan i god tid før arbeidet starter og potensielt at autorisasjonsteamene sine egne ressurser kan bistå i nytt oppsett.

Andre problemstillinger som må diskuteres:

annerisbakk commented 6 months ago

@Herskis

SandGrainOne commented 1 month ago

@Herskis I see that this is not included in your teams board.