OCPCRT-436: Add request/revoke commands for temporary GCP project access#593
OCPCRT-436: Add request/revoke commands for temporary GCP project access#593AlexNPavel wants to merge 2 commits intoopenshift:mainfrom
Conversation
|
@AlexNPavel: This pull request references OCPCRT-436 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/hold |
e54ad3d to
d198739
Compare
|
The |
|
/retest |
d198739 to
6ea0246
Compare
|
@AlexNPavel: This pull request references OCPCRT-436 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "4.22.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
edc05e9 to
009e7cc
Compare
bradmwilliams
left a comment
There was a problem hiding this comment.
Definitely think we should consider refactoring the parser.SlackClient piece at some point, but it's not critical to this effort.
|
/retest |
Add new `request` and `revoke` text commands that allow members of the Hybrid Platforms organization to obtain temporary access to GCP projects for testing complex or long-lived clusters beyond what the existing automated commands support. Commands: - `request <resource> "<justification>"` - Request 7-day access with business justification - `revoke <resource>` - Remove access early before expiration Key features: - Authorization via Cyborg API to verify Hybrid Platforms organization membership - Service account-based access with key file distribution via Slack - Automated IAM binding creation with 7-day default expiration - Background monitoring and cleanup of expired access grants - Initial support for "gcp-access" resource with extensible design Implementation includes: - New GCP access manager with IAM policy management (pkg/manager/gcp_access.go) - Service account creation, key generation, and cleanup operations - Request/revoke command parsers and action handlers - BigQuery audit logging for access grants - Comprehensive test coverage (627 lines of manager tests, 941 lines of Slack action tests) - Documentation in docs/claude/OCPCRT-436/ for implementation details and testing procedures This PR also includes modernization recommendations from the `gopls` modernizer.
009e7cc to
dad9962
Compare
|
/label tide/merge-method-squash |
|
I rebased onto main and updated the hack/govulncheck-wrapper.sh to use |
|
@AlexNPavel: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: AlexNPavel, bradmwilliams The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Add new
requestandrevoketext commands that allow members of theHybrid Platforms organization to obtain temporary access to GCP projects
for testing complex or long-lived clusters beyond what the existing
automated commands support.
Commands:
request <resource> "<justification>"- Request 7-day access with business justificationrevoke <resource>- Remove access early before expirationKey features:
Implementation includes:
This PR also includes modernization recommendations from the
goplsmodernizer.