Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Move DSS whitelist to AWS Secrets Manager or Auth0 #1487

Closed
1 of 2 tasks
mweiden opened this issue Aug 6, 2018 · 8 comments
Closed
1 of 2 tasks

Move DSS whitelist to AWS Secrets Manager or Auth0 #1487

mweiden opened this issue Aug 6, 2018 · 8 comments
Assignees

Comments

@mweiden
Copy link
Contributor

mweiden commented Aug 6, 2018

User Story

  • As an operator of the DSS
  • I would like the whitelist secrets to be stored in AWS Secrets Manager or Auth0
  • so that no sensitive identifiers are stored in the repository and that others can deploy the code without inheriting vestigial configuration.

Definition of done

@kozbo kozbo added this to the Sprint 7 - Aug 17 milestone Aug 7, 2018
@mweiden mweiden changed the title Move DSS whitelist to AWS Secrets Manager Move DSS whitelist to AWS Secrets Manager or Auth0 Aug 20, 2018
@Bento007
Copy link
Member

When deploying changes to auth0 import the whitelisted email domain and admin email from secrets and add it to the rules.

@Bento007
Copy link
Member

removed DSS_SUBSCRIPTION_AUTHORIZED_DOMAINS_ARRAY variable

@Bento007
Copy link
Member

Bento007 commented Sep 4, 2018

Where do we currently store admin-emails?

@Bento007
Copy link
Member

Change admin list to a group and store in auth0

@mweiden
Copy link
Contributor Author

mweiden commented Sep 17, 2018

@Bento007
Copy link
Member

I need to check of this is actually need considering we have dcp-infra which maintains a whitelist of admin users.

@Bento007
Copy link
Member

I need to close this and create new tickets to remove the admin operations from the API.

@Bento007
Copy link
Member

See #1736

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants