Skip to content

Per-host IAM roles instead of the shared production role #10

Description

@adamjohnwright

Each host should be able to write only its own data/<host>/ and raw/<host>/. Hosts sharing the production instance role currently keep prefix-wide access; recorded as an accepted exception in specs/000-status-page-baseline/tasks.md (T014). Splitting the role means changing instance profiles on running production machines. Mitigation in place: uploads are served as inert JSON.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityHardening and permissions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions