Skip to content

Conversation

mikkeloscar
Copy link
Contributor

This adds bucket policies to the s3 buckets that are part of the Kubernetes core infra. The policies prevent users who shouldn't have access from tampering with objects.

Only Administrator and respective service roles should have access to the bucket contents.

This also removes the legacy Shibboleth-Administrator role in a few places.

TODO

  • Validate that etcd backup/restore script works with the policy in place.

@mikkeloscar mikkeloscar added do-not-merge major Major feature changes or updates, e.g. feature rollout to a new country, new API calls. labels Dec 9, 2024
Signed-off-by: Mikkel Oscar Lyderik Larsen <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
do-not-merge major Major feature changes or updates, e.g. feature rollout to a new country, new API calls.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant