Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Promotion 2023-11-01 #5643

Closed
14 tasks
dsotirho-ucsc opened this issue Oct 23, 2023 · 2 comments
Closed
14 tasks

Promotion 2023-11-01 #5643

dsotirho-ucsc opened this issue Oct 23, 2023 · 2 comments
Assignees
Labels
API API change affecting callers infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team task [type] Resolution requires engineering action other than code changes

Comments

@dsotirho-ucsc
Copy link
Contributor

  • Security design review completed; the Resolution of this issue does not
    • … affect authentication; for example:
      • OAuth 2.0 with the application (API or Swagger UI)
      • Authentication of developers with Google Cloud APIs
      • Authentication of developers with AWS APIs
      • Authentication with a GitLab instance in the system
      • Password and 2FA authentication with GitHub
      • API access token authentication with GitHub
      • Authentication with
    • … affect the permissions of internal users like access to
      • Cloud resources on AWS and GCP
      • GitLab repositories, projects and groups, administration
      • an EC2 instance via SSH
      • GitHub issues, pull requests, commits, commit statuses, wikis, repositories, organizations
    • … affect the permissions of external users like access to
      • TDR snapshots
    • … affect permissions of service or bot accounts
      • Cloud resources on AWS and GCP
    • … affect audit logging in the system, like
      • adding, removing or changing a log message that represents an auditable event
      • changing the routing of log messages through the system
    • … affect monitoring of the system
    • … introduce a new software dependency like
      • Python packages on PYPI
      • Command-line utilities
      • Docker images
      • Terraform providers
    • … add an interface that exposes sensitive or confidential data at the security boundary
    • … affect the encryption of data at rest
    • … require persistence of sensitive or confidential data that might require encryption at rest
    • … require unencrypted transmission of data within the security boundary
    • … affect the network security layer; for example by
      • modifying, adding or removing firewall rules
      • modifying, adding or removing security groups
      • changing or adding a port a service, proxy or load balancer listens on
  • Documentation on any unchecked boxes is provided in comments below
@dsotirho-ucsc dsotirho-ucsc added the orange [process] Done by the Azul team label Oct 23, 2023
@dsotirho-ucsc dsotirho-ucsc changed the title Promotion 10/25/2023 Promotion 11/01/2023 Oct 30, 2023
@dsotirho-ucsc
Copy link
Contributor Author

Assignee to obtain ETA from CC.

@dsotirho-ucsc dsotirho-ucsc changed the title Promotion 11/01/2023 Promotion 2023-11-01 Oct 31, 2023
@bvizzier-ucsc
Copy link

bvizzier-ucsc commented Oct 31, 2023

CC has completed the portal work for the release of dcp32: DataBiosphere/data-portal#2214

Edit: CC is scheduling anvil3 release and will be done this week assuming no issues are found: DataBiosphere/data-browser#3726

@dsotirho-ucsc dsotirho-ucsc added API API change affecting callers task [type] Resolution requires engineering action other than code changes infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator labels Nov 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
API API change affecting callers infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team task [type] Resolution requires engineering action other than code changes
Projects
None yet
Development

No branches or pull requests

3 participants