Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-70251

List of minimum IAM Permissions for CCO in HCP Manual Mode for least privilege.

XMLWordPrintable

    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Proposed title of this feature request

      List of minimum IAM Permissions for CCO in HCP Manual Mode for least privilege

      2. What is the nature and description of the documentation request?

      For the Cloud Credential Operator (CCO)  when running in the Manual mode should provide the exact policy permissions for the CCO operator as it requires a set of read-only permissions to validate the existing environment and secrets. The information can be checked in following document in chapter 10:

      10.3. ASSIGNING COMPONENTS IAM ROLES BY USING THE CCO IN A
      HOSTED CLUSTER ON AWS

        • What should be improved:* The documentation should explicitly include the following Minimum Read-Only Policy for the CCO Operator (cloud-credential-operator-iam-ro role) as this could be changed in audits or  could  have colissions with IAM policies.

      If not, customers may grant full permissions (like iam:*) to the CCO operator to "ensure it works" which would be a security risk.
       

              ocp-docs-bot OCP DocsBot
              rhn-support-dahernan David Hernandez Fernandez
              None
              None
              Jie Zhao Jie Zhao
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: