Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add exemption tags for OIDC dev and RP version storage accounts #3585

Merged
merged 4 commits into from
May 21, 2024

Conversation

niontive
Copy link
Contributor

Which issue this PR addresses:

Fixes https://issues.redhat.com/browse/ARO-7388

What this PR does / why we need it:

  • Add exempt tags to storage accounts that have public blob anonymous access. This prevents an s360 violation.
  • The two storage accounts are dev OIDC and RP version. These are meant to have public access

Test plan for issue:

These are infra changes - will test via rollout in INT

Is there any documentation that needs to be updated for this PR?

https://msazure.visualstudio.com/AzureRedHatOpenShift/_wiki/wikis/AzureRedHatOpenShift.wiki/675077/S360-Disable-anonymous-public-blob-access

How do you know this will function as expected in production?

We're going to test in INT and cross fingers the exemption goes through. Also, this change just adds a tag - it's not affecting the configuration of the storage accounts.

@niontive niontive changed the title Niontive/aro 7388 Add exemption tags for OIDC dev and RP version storage accounts May 17, 2024
Copy link
Collaborator

@bennerv bennerv left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Copy link
Collaborator

@cadenmarchese cadenmarchese left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@cadenmarchese
Copy link
Collaborator

/azp run ci,e2e

Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@cadenmarchese
Copy link
Collaborator

/azp run e2e

Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@cadenmarchese cadenmarchese merged commit e88bd57 into master May 21, 2024
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants