Skip to content

Epic - GCP Permissions Match Conceptual Plan #5691

Description

@mrtopsyt

Epic - GCP Permissions Match Security Plan

As an engineer concerned about security, I want to make sure that our GCP permissions align with the Conceptual Permissions Plan for payments data.

Acceptance Criteria

Groups

Secrets / Service Accounts

  • Only users who are in the Cal-ITP Payments Workers group and Admin group can access secrets that grant non-destructive access to payments data
    • Metabase API keys with payments access (reader/writer keys, agency keys)
    • LPay AWS keys
  • Only users who are in the Admin group can access secrets for payments infrastructure
    • Elavon + Enghouse SFTP private keys
    • Metabase Admin Keys
  • Only users who are in the Cal-ITP Payments Workers group and Admin group can generate and view keys for payment agency service accounts

Buckets

  • There is a list of existing buckets on prod and staging that are important for non-payments analyst work (bucket access is on a whitelist basis, because most buckets are not important for analyst work)
  • Users in the Data Workers and Flex groups can only access buckets in the list of buckets that are important for non-payments analyst work
    • On staging
    • On prod
  • Buckets that are important for non-payments analyst work do not contain payments data on prod and on staging

Tables

  • Users in the Data Workers and Flex groups cannot access external, staging, and mart tables in the payments and benefits groups; they can access all other tables (table access is on a blacklist basis, because sensitive data should always be in those two categories)
    • On staging
    • On prod
  • Users in the Cal-ITP Payments Workers and Admin Groups can access all tables
    • On staging
    • On prod

Documentation / Wrap up

  • A review has been conducted of other pathways for access to sensitive payments data on prod and on staging
  • The Conceptual Permissions Plan is updated with these changes (under Current Status)
  • Documentation exists on how to configure permissions for new data sources

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions