Closed markdboyd closed 1 year ago
@apburnes Can you add Dorothy's github account, dtamasang2
, to the platform-ops team in GitHub? It seems like you have admin privileges to add members to that team
@markdboyd Dorothy's been invited and there will be an email from Github to accept the invitation.
bash-3.2$ git config commit.gpgsign true bash-3.2$
New Platform Operator Onboarding Checklist
In order to get Dorothy productively contributing to the cloud.gov team, @markdboyd should help Dorothy complete a prescribed set of tasks that will bring them up to speed and get them setup with cloud.gov.
Instructions
Onboarding Checklist
Required items for all team members
These items help us fulfill security and compliance requirements (including for FedRAMP). If you get stuck, or if these requirements are confusing, ask for help from your buddy or in a cloud.gov channel.
Pre-requisites
Fulfill security and compliance requirements (including for FedRAMP) - Completed by onboarding buddy
cloud-gov
organization in GitHub, and thecloud-gov-team
team.Learn our policies and procedures
For the three trainings list at the top, your onboarding buddy will create a separate ticket to track the trainings once scheduling has been finished. This will help consolidate trainings for multiple new members to the team and prevent them from blocking progress on this onboarding ticket. Once the trainings are scheduled, they can be marked as complete here.
Getting to know cloud.gov
These items will help you come up to speed on cloud.gov and what it is, how it works, why it exists, etc. While you should take the time to go through them, please do not try and tackle it all in one shot! It can become overwhelming very quickly, so your onboarding buddy will walk through this list with you at a high level with you to help manage the work.
Slack channels
Your onboarding buddy will add you to these Slack channels:
#cloud-gov
- bots post announcements here#cg-billing
- private business development channel (if applicable)#cg-business
- business development (if applicable)#cg-compliance
- compliance-related information and discussion#cg-offtopic
- off-topic team sharing#cg-platform
- platform operations#cg-platform-news
- bots post platform alerts#cg-general
- program-level information and discusion#cg-support
- support requests and assistance within TTS#cg-incidents
- private channel for incident response#cg-priv-all
- private channel for in-team discussion#cg-priv-gov
(Federal employees only) - may contain discussion of contracting-related or other private, federal-employee-only commsOnce you're added to these channels, you probably want to mute these channels until you're on support rotation:
#cg-support
- support requests and assistance within TTS#cg-platform-news
- platform alertsPlatform-Ops-specific items
You should already have admin rights on your machine as a part of its original setup. If for whatever reason you don't, Please let your onboarding buddy know and they will help you request local admin rights on your GFE Mac using this justification.
Cloud Operations account management
Note: These are all contingent on completing the GSA Mandatory Cyber Security and Privacy Training first. AWS user names should be identical across accounts so that permissions can be correctly managed by Terraform.
platform-ops
team in GitHub.agent
to the cloud.gov support Zendesk (Ask a cloud.gov member with admin access to Zendesk to add them).Your onboarding buddy will create a separate ticket tied to this one to track the AWS accounts being granted full admin access.
Additional compliance setup/review
caulking
git leak prevention by following the READMEcaulking
by runningmake audit
and pasting a screenshot as a comment on this GitHub issuegit config commit.gpgsign
as a comment on this GitHub issueInstall a development environment for cloud.gov
brew
)brew tap cloudfoundry/tap
brew install cf-cli@7
brew install openssl
cf login -a api.fr.cloud.gov --sso
cf orgs
brew install cloudfoundry/tap/bosh-cli
bosh -v
in the command linebrew install terraform
brew install awscli
brew install jq
terraform
and helper text should displayaws
and helper text should displayaws-vault
by following our directions[x] Install the Concourse
fly
CLIbrew install fly
fly -h
in your command lineThis may fail due to app security policy on your mac rejecting apps from unidentified developers. To fix it (replace
<VERSION>
with your installed version offly
):xattr -d com.apple.quarantine /usr/local/Caskroom/fly/<VERSION>/fly
cg-scripts
repo: rungit clone https://github.com/cloud-gov/cg-scripts.git
in your command lineFigure out your first tasks
Please work with your onboarding buddy to determine a platform component to work on first. Once you've identified the component you're going to focus on, your onboarding buddy will introduce you to someone who can onboard you to that project in specific. For the next few sprints, work on features, bugs, and improvements on this component. Reach out to your onboarding buddy or anyone else on the team if you need any help. Here are some easily-separated pieces to consider:
Compliance items
These are items that are only necessary for someone stepping into a compliance role, but you can still subscribe to the alerts and mailing lists if you're interested: