[UMETRICS-3] Overhaul AWS setup permissions Created: 29/May/19 Updated: 18/Jul/19 Resolved: 12/Jun/19 |
|
| Status: | Closed |
| Project: | Usage Metrics |
| Component/s: | module |
| Affects Version/s: | None |
| Fix Version/s: | None |
| Type: | Improvement | Priority: | Neutral |
| Reporter: | Maxime Michel | Assignee: | Maxime Michel |
| Resolution: | Obsolete | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Template: |
|
| Acceptance criteria: |
Empty
|
| Task DoD: |
[ ]*
Doc/release notes changes? Comment present?
[ ]*
Downstream builds green?
[ ]*
Solution information and context easily available?
[ ]*
Tests
[ ]*
FixVersion filled and not yet released
[ ] 
Architecture Decision Record (ADR)
|
| Description |
|
The current ES instance was linked to Cognito and IAM roles after a lot of trial and error, eventually leading to a temporary administrative user in the account. To actually test the use case before 6.1, this instance is going to be used from now on. But when we are in production for real, we might want to recreate a clean instance without any admin right, and double-check that the policies are correct. |
| Comments |
| Comment by Maxime Michel [ 12/Jun/19 ] |
|
The instance will be hosted on the SRE platform in the near future. By then security will be done with Terraform. |