Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cloudtrail config updates for HydroVis #1004

Open
DrixTabligan-NOAA opened this issue Dec 4, 2024 · 8 comments
Open

Cloudtrail config updates for HydroVis #1004

DrixTabligan-NOAA opened this issue Dec 4, 2024 · 8 comments
Assignees
Labels
Task 2 GAMA Task 2
Milestone

Comments

@DrixTabligan-NOAA
Copy link
Collaborator

From chat:

Morning @diwakar puthalapat - NOAA Affiliate - got a question when you get the chance to reply (I know you are in reinvent)... YTD we have paid over $30k for cloudtrail in hydrovis dev. looks like there have been manually configured cloudtrails which are not part of the terraform deployment.

  1. I tried deleting trails not common to all three environments with the assumption that these were put in manually. however, looks like my role/privileges do not have rights to delete them. looking at the individual configs it seems that they are just duplications of the other.

  2. there's a couple of common trails NOAA-CASB-Cloudtrail and aws-controltower-BaselineCloudTrail which should suffice I assume. However, for audit purposes, if we need access to these to view cloudtrail logs, same account does not have privileges to view.

would you mind taking a look at both of these?

@DiwakarPuthalapat-NOAA
Copy link

NOAA-CASB-CloudTrail and aws-controltower-BaselineCloudTrail are managed by OCIO WOC

@DiwakarPuthalapat-NOAA
Copy link

@DiwakarPuthalapat-NOAA
Copy link

@DrixTabligan-NOAA
Copy link
Collaborator Author

Will work with WOC to update the config.

@derekgiardino derekgiardino added the Task 2 GAMA Task 2 label Dec 4, 2024
@derekgiardino derekgiardino added this to the V2.1.8 milestone Dec 4, 2024
@DiwakarPuthalapat-NOAA
Copy link

Created RITM0327068 for WOC

@derekgiardino
Copy link
Collaborator

Is this ticket completed now?

@DrixTabligan-NOAA
Copy link
Collaborator Author

DrixTabligan-NOAA commented Dec 6, 2024 via email

@DiwakarPuthalapat-NOAA
Copy link

All trails have been deleted and following S3 buckets have been deleted:

  • aws-cloudtrail-logs-noaa-nws-hydrovis
  • aws-cloudtrail-logs-hydrovis

I think we should create separate ticket to track access to CloudTrail bucket. @derekgiardino I think request to access CloudTrail has to be initiated by a Fed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Task 2 GAMA Task 2
Projects
None yet
Development

No branches or pull requests

3 participants