-
Notifications
You must be signed in to change notification settings - Fork 108
OCPCRT-436: Add request/revoke commands for temporary GCP project access #593
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
@AlexNPavel: This pull request references OCPCRT-436 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/hold |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: AlexNPavel The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Add new `request` and `revoke` text commands that allow members of the Hybrid Platforms organization to obtain temporary access to GCP projects for testing complex or long-lived clusters beyond what the existing automated commands support. Commands: - `request <resource> "<justification>"` - Request 7-day access with business justification - `revoke <resource>` - Remove access early before expiration Key features: - Authorization via Cyborg API to verify Hybrid Platforms organization membership - Automated IAM binding creation with 7-day default expiration - Background monitoring and cleanup of expired access grants - Initial support for "gcp-access" resource with extensible design for additional GCP projects or resource types Implementation includes: - New GCP access manager with IAM policy management (pkg/manager/gcp_access.go) - Request/revoke command parsers and action handlers - Comprehensive test coverage (627 lines of manager tests, 941 lines of Slack action tests) - Documentation in docs/claude/OCPCRT-436/ for implementation details and testing procedures
e54ad3d to
d198739
Compare
|
The |
|
/retest |
|
@AlexNPavel: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Add new
requestandrevoketext commands that allow members of the Hybrid Platforms organization to obtain temporary access to GCP projects for testing complex or long-lived clusters beyond what the existing automated commands support.Commands:
request <resource> "<justification>"- Request 7-day access with business justificationrevoke <resource>- Remove access early before expirationKey features:
Implementation includes:
This PR also has a modernization recommendations from the
goplsmodernizer implemented.