Permissions docs

This commit is contained in:
2024-09-18 12:34:32 -04:00
parent 1da31679cb
commit 09d18e5d3a
4 changed files with 408 additions and 0 deletions

View File

@@ -0,0 +1,23 @@
#+TITLE: Testing IAM-Runtime checks for Metal API
#+AUTHOR: Adam Mohammed
* What's changed
* Stages of testing
- Initial Canary
- Run terraform against internal canary URL
- Slow roll to production
- Watch for errors
- In-production warn mode
- Observe for discrepancies between cancancan/iam-runtime
- Runtime winning mode
- Completed
* Monitoring
- Trace attributes that are relevant
- Dashboards
- Create dashboard around cancancan disagreements
- Create dashboard where resource was not metal org/project/user
* Handling broken cases