ministryofjustice / analytical-platform

Analytical Platform • This repository is defined and managed in Terraform
https://docs.analytical-platform.service.justice.gov.uk
MIT License
8 stars 4 forks source link

✨ Migrate resources from data-engineering-infra and grant permissions to SSO data engineering role #3765

Closed SoumayaMauthoorMOJ closed 3 months ago

SoumayaMauthoorMOJ commented 4 months ago

Describe the feature request.

Migrate resources from data-engineering-infra to data-platform IAC and add relevant permissions to SSO data engineering role

Bucket and bucket policies

For all buckets apart from mojap-nomis-gdpr:

image

image

image

Glue database policy

For all databases and specified role_names, apart from restricted_admin:

image

Describe the context.

See following tickets for more context:

Value / Purpose

No response

User Types

No response

julialawrence commented 4 months ago

@SoumayaMauthoorMOJ the following buckets don't exist in the data-production account:

Please advise how you'd like to proceed.

SoumayaMauthoorMOJ commented 4 months ago

@julialawrence If they don't already exist don't create them :-)

julialawrence commented 4 months ago

The glue policy has been imported and the data eng role added. This needs to continue into next sprint.

jacobwoffenden commented 4 months ago

Moving to blocked while @julialawrence is on annual leave.