StatCan / aaw-profile-state-controller

Controller for adding states to profiles for privileged access
Other
0 stars 1 forks source link

chore(documentation): update documentation #9

Closed saffaalvi closed 2 years ago

saffaalvi commented 2 years ago

Documentation update: https://github.com/StatCan/daaas/issues/1068

watches for SAS notebooks - if SAS notebook is present, then non-employee cannot be added. If non-employee is in namespace, then user cannot create SAS notebook

watches for rolebindings in profile namespace - if any non-employee user is present in namespace role binding, then add label saying this is a non-employee namespace

this controller sets labels that Gatekeeper uses to enforce policies