-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Open
Open
[Cloud Connectors Management Lifecycle] Investigtion Kibana-managed lifecycle with Otel Verifier #254236
Discovery
Copy link
Labels
Team:Cloud SecurityCloud Security team relatedCloud Security team related
Description
Motivation: We need to understand how Fleet/Kibana could manages the full Verifier Permission and Status lifecycle. We need a background task to trigger Verifier Permission and Status lifecycle and propose high-level system design flow.
Definition of Done:
- Review Integrations PR and Reciever PR
- Review Suggestion Options A and C Implementation Plan
- Background Job
- Add feature flag to gate feature until QA
- Performance Impact Queue - Limit and verify one agent at time
- Scheduling task vs on-demand
- Clean up policies and custom resources, Agentless Deployment is short-lived
- Logging
- Happy Flow Scenarios
- Unhappy Flows Scenarios ( authentication issues, authorization issues, retries, verifier has bug = blast radius affecting cloud connector associated agentless deployments, TTL timeouts, namespace, evaluate any other background task that could affect this bg task, etc)
- Propose Design High level System Diagram Fleet Management Lifecycle for
- Querying Data flow
- Verifier permissions should support only AWS integrations for now
- BG Task Sub-Agent Poc Workflow
* Alignment - Sync with stakeholders and create a planning and creating tickets for bg task
* Skill - Claude code System Diagram & HTML Plan => BG Task Implementation in Kibana => Run Locally
* Skill - BG Task Implementation in Kibana > Output Overview BG Task High level architecture with Log Analysis
* Skill - BG Task Implementation in Kibana > Output Figma Design (if needed)
* Skill - BG Task Implementation in Kibana > Draft PR
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Team:Cloud SecurityCloud Security team relatedCloud Security team related