alkem-io / alkemio

START HERE! Cross project collaboration and shared documentation.
European Union Public License 1.2
23 stars 4 forks source link

Accounts cleaned up on Azure #359

Closed techsmyth closed 3 years ago

techsmyth commented 3 years ago

Description

As a CT Service Manager I want to have only alkem.io accounts for the dev team access azure so that there is no clutter and obsolete accounts with elevated privileges there.

Acceptance criteria

Additional Context

valentinyanakiev commented 3 years ago

Created 4 Groups in AAD

Neil is everywhere with the Neil_Admin account. I have removed access for my (valentin_yanakiev@yahoo.co.uk) personal account. I have access with valentin@alkem.io and only access with alkem.io is used. Also cleaned up some 'dead' accounts on subscription level.

Now providing access to the specific envs can be done by simply adding people to the group.

NB. This is not in terraform. Ideally should be done / linked there, but that won't be a quick fix. Let's first validate whether, security - wise, this makes sense.