Moshe Eshel
08/28/2023, 12:58 PMMoshe Eshel
08/28/2023, 1:02 PMBill Tarr
08/28/2023, 3:43 PMMoshe Eshel
08/28/2023, 3:52 PMMoshe Eshel
08/28/2023, 3:53 PMBill Tarr
08/28/2023, 3:54 PMBill Tarr
08/28/2023, 3:55 PMMoshe Eshel
08/28/2023, 3:56 PMGwen Shapira
08/28/2023, 3:59 PMBill Tarr
08/28/2023, 5:09 PMWe need to work with an approved SecOps procedure in our code, and with a closed set of permissions
Perhaps in that case what @Gwen Shapira is suggesting would be a good option... Simply make policy management it's own pipeline with approval? Certainly worth a look.
Regarding having security review the code and approve dynamic policy creation - that one we know - but SecOps are really set against, mostly because they are afraid of someone using these permissions outside of our code...
Understood. I'd argue the exposure with ABAC is limited, but a non-zero exposure for sure (and ABAC role could still be assumed by rogue code). My Tel Aviv based co-worked @Alex Pulver just did this sample on Github... Not sure ABAC would convince your SecOPS, just an FYI.Gwen Shapira
08/28/2023, 5:34 PMGwen Shapira
08/28/2023, 5:34 PMMoshe Eshel
08/28/2023, 5:43 PMGwen Shapira
08/28/2023, 5:45 PMGwen Shapira
08/28/2023, 5:46 PMMoshe Eshel
08/28/2023, 5:48 PMBill Tarr
08/28/2023, 5:58 PMGwen Shapira
08/28/2023, 5:59 PMMoshe Eshel
08/28/2023, 6:01 PMBill Tarr
08/28/2023, 6:06 PMBill Tarr
08/28/2023, 6:06 PMMoshe Eshel
08/28/2023, 6:08 PMAlex Pulver
08/28/2023, 6:53 PMMoshe Eshel
08/28/2023, 6:57 PMAnoop Dawar
10/03/2023, 3:18 PM