Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow consumption roles to be used in shares with data.all not creating / managing policies for that role #1613

Open
TejasRGitHub opened this issue Oct 5, 2024 · 0 comments

Comments

@TejasRGitHub
Copy link
Contributor

TejasRGitHub commented Oct 5, 2024

Is your idea related to a problem? Please describe.
In data.all , consumption role in an environment. Consumption roles when registered, data.all creates a managed policy for the consumption role and if the role is data.all managed then data.all attaches the policy to the consumption role.

We have few roles which have super user permissions or are managed by the users themselves. They do not want data.all to manage the IAM policies for that role.

Describe the solution you'd like
While importing a consumption role, add another check "Allow without policies" ( or some other name ) with which user can onboard a consumption role and use it as a part of share.

When the share is approved, the bucket, KMS , LF , etc will be modified but the consumption role won't be attached any policy as well as a policy won't be created. This policy creation and attachment will be done by the requestor

P.S. Don't attach files. Please, prefer add code snippets directly in the message body.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant