bcgov / cloud-pathfinder

This is the technology and UX backend repo for the cloud pathfinder ZenHub task board
https://app.zenhub.com/workspaces/cloud-pathfinder-5e4dbb426c3c6af8dcbf06a7/board?repos=241742911
Creative Commons Zero v1.0 Universal
2 stars 8 forks source link

Enforce IDIR login for GCP usrs #2865

Closed NickCorcoran closed 7 months ago

NickCorcoran commented 7 months ago

Describe the Issue Since initial use, Google local accounts have been used for authentication for GCP. Policy requires IDIR integration for corporately supported cloud services, so integration is necessary.

Additional Context Add any other context, attachments or screenshots

Acceptance Criteria

^ Done previously by Nick and Warren ^ v Done this sprint v

NickCorcoran commented 7 months ago

All IDIR users identified w/ Google Workspace accounts have been assigned to the IDIR enforcement group.

However, I think there may be some users directly granted resource access in projects. To be investigated.

Also, Google workspace admin accounts cannot be forced to login w/ alternative IDP. May have to adjust to ensure those admin accounts are used as break glass use (TBD).