Uploaded image for project: 'Nuxeo ECM Build/Test Environment'
  1. Nuxeo ECM Build/Test Environment
  2. NXBT-3332

Configure Napps Jenkins X GitHub authentication to protect administrator access

    XMLWordPrintable

    Details

    • Type: Task
    • Status: Resolved
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Jenkins X
    • Tags:
    • Impact type:
      Configuration Change
    • Upgrade notes:
      Hide

      Done: Only Napps team members have administrator access.
      if a new user did not have admin access, please open new PR on jx-napps-jenkins and it on config/jenkins.yaml

      Show
      Done: Only Napps team members have administrator access. if a new user did not have admin access, please open new PR on jx-napps-jenkins and it on config/jenkins.yaml
    • Sprint:
      nxApps 2020 Cycle 6
    • Story Points:
      2

      Description

      Currently, with the OOTB configuration, logged-in users can do anything.

      We want to apply a configuration similar to QA to have only GitHub administrators and the team developers to have administrator access.

      This CasC snippet should be OK:

      jenkins:
        authorizationStrategy:
          github:
            adminUserNames: "doulba, nmpcunha, RSalem07, PGoncalvesNX"
            allowAnonymousJobStatusPermission: false
            allowAnonymousReadPermission: false
            allowCcTrayPermission: true
            allowGithubWebHookPermission: true
            authenticatedUserCreateJobPermission: false
            authenticatedUserReadPermission: false
            useRepositoryPermissions: true
      

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 5 hours
                5h