Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Presentation] cert-manager Graduation Overview #1254

Open
2 of 3 tasks
SgtCoDFish opened this issue May 8, 2024 · 10 comments
Open
2 of 3 tasks

[Presentation] cert-manager Graduation Overview #1254

SgtCoDFish opened this issue May 8, 2024 · 10 comments
Labels
triage-required Requires triage usecase-presentation Label for usecase related presentations

Comments

@SgtCoDFish
Copy link

SgtCoDFish commented May 8, 2024

Title: cert-manager Graudation Overview

Speakers:

Other attendees from the cert-manager project:

Description: An overview of what cert-manager is and does, mostly with the aim of facilitating connections, questions and input from tag-security. Related to (and required by) cert-manager's Graduation Application.

Time: 10 mins, with extra time after for questions if required.

Availability: European timezones preferred!

TO DO:

  • TAG Representative
  • Schedule date - pencilled in for 2024-05-22 EMEA meeting
  • By opening this issue, I, (Ashley Davis - @SgtCoDFish) acknowledge that the presentation topic and speaker will follow the presentation guidelines
@SgtCoDFish SgtCoDFish added triage-required Requires triage usecase-presentation Label for usecase related presentations labels May 8, 2024
@sublimino
Copy link
Member

Hi @SgtCoDFish, sounds great!

EMEA meetings are currently free for the next few weeks, please choose a time in the meeting document.

As part of the graduation in cncf/toc#1306 we can support you in the Document Security Self-Assessment phase, and walk through a self-assessment doc based on this template and this process.

The cert-manager incubation due diligence document from a couple of years ago might be useful as a baseline to support the graduation documents too. Any questions please ask, we're here to help 🙏

@SgtCoDFish
Copy link
Author

Thanks very much for the quick reply 😁

I've put us in for 2024-05-22 and we'll prepare for then!

As part of the graduation in cncf/toc#1306 we can support you in the Document Security Self-Assessment phase, and walk through a self-assessment doc based on this template and this process.

That sounds great, thank you for pointing to that because I'd been meaning to investigate it! I guess there's nothing stopping us getting started with the self-assessment now (before the 22nd), right?

@sublimino
Copy link
Member

That sounds great, thank you for pointing to that because I'd been meaning to investigate it! I guess there's nothing stopping us getting started with the self-assessment now (before the 22nd), right?

Absolutely! And if you share the doc link for public comment we can support async before the 22nd too 🙏

@maelvls
Copy link

maelvls commented May 16, 2024

Hey, here is the self-assessment doc: https://hackmd.io/_e-m6hnzRzqsosUv3aG60A?view. I'm struggling and need help with the subsections "Actors" and "Actions". Are the actors the same as in the security audit report: cert-manager contributors, untrusted users outside of cluster, limited privilege cluster users, cert-manager maintainers, third-party contributors, third-party maintainers? Let me know if you are available on the Kubernetes Slack.

@mrcdb
Copy link
Contributor

mrcdb commented May 20, 2024

hi @maelvls , thanks for sharing the self-assessment doc.

The self-assessment guide describes actors as "the individual parts of your system that interact to provide the desired functionality", so I would consider them as the different components of cert-manager rather than the threat actors. Actions then should delineate which interactions exist between the actors.

I am available on the CNCF Slack

@SgtCoDFish
Copy link
Author

Thanks for having us on the EMEA meeting today!

I'm taking away the following actions:

  1. Move from HackMD to a Google Doc for the self assessment
  2. Ask for feedback on the completed self assement Google doc

I'll comment on this issue when I've done those. I'll also update the graduation application to reflect the meeting and self assessment!

@SgtCoDFish
Copy link
Author

Here's the Google doc for our self-assesment - the above HackMD can now be ignored!

https://docs.google.com/document/d/1Sl1SqYbPSbBMoZroBU8M1dMw5DN-uUgoR1KLHoo5tr0/edit?usp=sharing

Anyone should be able to comment on it - any problems, let me know!

@mrcdb
Copy link
Contributor

mrcdb commented May 22, 2024

Here's the Google doc for our self-assesment - the above HackMD can now be ignored!

https://docs.google.com/document/d/1Sl1SqYbPSbBMoZroBU8M1dMw5DN-uUgoR1KLHoo5tr0/edit?usp=sharing

Anyone should be able to comment on it - any problems, let me know!

Thanks for the quick update, I appreciate the effort! This makes it easy for interested TAG volunteers to provide feedback directly to the maintainers. I will have a look at the document myself in the next couple of days and hopefully provide any input or ask for clarifications.

@mrcdb
Copy link
Contributor

mrcdb commented May 29, 2024

@SgtCoDFish thanks for the feedback on the self-assessment doc, I'm done with my review :)

Once you are happy with the revised document, please feel free to raise a PR to this repository to include the self-assessment doc in Markdown format to the /assessments/projects/ folder as described in the guide.

@SgtCoDFish
Copy link
Author

Thanks very much! I'll try to raise a PR soon 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
triage-required Requires triage usecase-presentation Label for usecase related presentations
Projects
None yet
Development

No branches or pull requests

4 participants