dmwm / CMSRucio

7 stars 31 forks source link

Document and check OIDC auth deployment procedure #648

Open dciangot opened 8 months ago

dciangot commented 8 months ago

Documentation Issue

We need to check that the init script and documentation for the integration with CMS-IAM is not Diego-centric

Current Documentation (if applicable)

Here there is the current rough documentation on how to produce the needed secrets

Description of the Issue

@ericvaandering and @dynamic-entropy are going to check wheter this is enough and actually working as expected. So that we have a minumum of expert available for a cluster migration.


ericvaandering commented 7 months ago

In the instructions https://github.com/dmwm/rucio-flux/blob/main/scripts/create_iam_clients/README.md there should be documentation for how to

Get a valid token with IAM profile and store it in TOKEN env var

dynamic-entropy commented 3 weeks ago

Hello @dciangot As discussed in the previous meeting, this can be closed. The current documentation is enough and less likely to change since this is the client creation step with the IAM.

And regarding what Eric asked, I think we get this from the IAM UI right, is there an API call too?

Cheers