DataBiosphere / azul

Metadata indexer and query service used for AnVIL, HCA, LungMAP, and CGP
Apache License 2.0
7 stars 2 forks source link

CC has excessive permissions in some deployment zones #6345

Open hannes-ucsc opened 3 months ago

hannes-ucsc commented 3 months ago

They currently have operator-like permissions to Google Cloud projects and AWS accounts platform-hca-dev and platform-hca-prod as well as some elevated permissions on GitHub and GitLab.

Before we can restrict their access to a level that is consistent with the approved and assessed security architecture, we need to take over the deployment of the following sites:

Since the first real MA snapshot for prod https://ucsc-gi.slack.com/archives/C705Y6G9Z/p1718723445761559, I'm hoping we can scrap the pilot site so that we don't need to over-complicate the process.

achave11-ucsc commented 3 months ago

Assignee to consider next steps.