Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update audit as of 2020-04-27 #807

Closed
wants to merge 3 commits into from

Conversation

spiffxp
Copy link
Member

@spiffxp spiffxp commented Apr 27, 2020

This was intended to pick up the results of running scripts/terraform introduced in #806

It also picked up:

  • removing some stray projectView permissions on k8s-conform buckets
  • that time where I accidentally the kubernetes-public project-wide ssh-keys metadata
    • I was trying to manually delete an old key from spiffxp-node-e2e-project but forgot the --project flag and was defaulted to kubernetes-public
    • I would restore the keys but they're listed as expiring on 2020-01-28

/cc @dims
to ack the ssh-keys removal
/cc @thockin @bartsmykla @cblecker
whomever is interested in reviewing the audit

remove groups from projectViewer role
... mea culpa, I accidentally nuked kubernetes-public's project-wide
ssh-keys metadata, dims will need to re-add
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Apr 27, 2020
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: spiffxp

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added area/audit Audit of project resources, audit followup issues, code in audit/ wg/k8s-infra approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Apr 27, 2020
"bindings": [
{
"members": [
"serviceAccount:kubernetes-public.svc.id.goog[test-pods/boskos-janitor]"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is it still called "test-pods"

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@@ -1,22 +1,22 @@
{
"commonInstanceMetadata": {
"fingerprint": "9_em4FUS_lU=",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Another candidate for being removed @bartsmykla

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ack

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done: #809

{
"createTime": "2020-04-26T17:09:06.114Z",
"lifecycleState": "ACTIVE",
"name": "spiffxp-boskos-project-01",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's not forget to clean these up :)

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is exactly why I put my name on them

@spiffxp
Copy link
Member Author

spiffxp commented Apr 30, 2020

/close
this is out of date, I'll open another audit PR tomorrow

@k8s-ci-robot
Copy link
Contributor

@spiffxp: Closed this PR.

In response to this:

/close
this is out of date, I'll open another audit PR tomorrow

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@spiffxp spiffxp mentioned this pull request May 7, 2020
@spiffxp spiffxp deleted the audit-2020-04-27 branch May 28, 2020 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. area/audit Audit of project resources, audit followup issues, code in audit/ cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants