Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Draft of "Machine Identity" Decision Record #140

Draft
wants to merge 9 commits into
base: main
Choose a base branch
from

Conversation

joshmue
Copy link
Contributor

@joshmue joshmue commented Sep 23, 2022

Signed-off-by: Joshua Mühlfort [email protected]

Signed-off-by: Joshua Mühlfort <[email protected]>
@fkr fkr self-assigned this Sep 23, 2022
@fkr fkr self-requested a review September 23, 2022 11:03
@joshmue joshmue changed the title Add 0001_machine_identity.md ADR draft Add 0001_machine_identity.md ADR Sep 23, 2022
Signed-off-by: Joshua Mühlfort <[email protected]>
@joshmue
Copy link
Contributor Author

joshmue commented Sep 26, 2022

@JuanPTM @reqa Would you mind to take a look? We could further discuss in the next ops/iam meetings.

@JuanPTM
Copy link
Contributor

JuanPTM commented Sep 26, 2022

Looks good to me.

Signed-off-by: Joshua Mühlfort <[email protected]>
@joshmue joshmue changed the title Add 0001_machine_identity.md ADR Add Draft of Machine Identity Decision Record Sep 30, 2022
Signed-off-by: Joshua Mühlfort <[email protected]>
@joshmue joshmue changed the title Add Draft of Machine Identity Decision Record Add Draft of "Machine Identity" Decision Record Sep 30, 2022
Signed-off-by: Joshua Mühlfort <[email protected]>
@joshmue
Copy link
Contributor Author

joshmue commented Sep 30, 2022

@horazont I adjusted this document to #143, please feel free to give feedback.

(I also "fixed" the need to spell out SPIFFE by omitting it)

@mbuechse
Copy link
Contributor

Is this still relevant? I will close this PR if nothing happens by July 31st.

@joshmue
Copy link
Contributor Author

joshmue commented Jun 26, 2024

It's still very relevant to the cloud's user experience and general security as outlined in the document itself.

Whether it's feasible for the SCS project to achieve in the short/medium term, is uncertain.

Two factors that could make it more easy:

  1. K8s clusters offer OIDC federation of ServiceAccounts
  2. The "Central API" may be configured to accept tokens from a central IdP

@mbuechse
Copy link
Contributor

So the topic is relevant, but what I meant was this PR. Can it be salvaged and merged, or do we expect it to lie dormant for the next months? In the latter case, it should probably be closed. Unfortunately, it doesn't mention any issue.

@joshmue
Copy link
Contributor Author

joshmue commented Jun 27, 2024

The content is not outdated in some way, as it is very high level. So, it is ok to be discussed and merged, IMHO.
I cannot say anything about prioritization/planning across weeks/months/years/project-phases, though.

@mbuechse mbuechse linked an issue Aug 28, 2024 that may be closed by this pull request
9 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Implement Machine Identities
4 participants