Add jpodivin access to AWS #13464
Labels
No labels
announcement
anubis
authentication
aws
backlog
blocked
bodhi
ci
cloud
communishift
copr
database
day-to-day
dc-move
deprecated
dev
discourse
dns
downloads
easyfix
epel
firmitas
forgejo_migration
Gain
High
Gain
Low
Gain
Medium
gitlab
greenwave
hardware
help wanted
high-trouble
koji
koschei
lists
low-trouble
medium-trouble
mirrorlists
monitoring
Needs investigation
odcs
OpenShift
ops
outage
packager_workflow_blocker
pagure
permissions
Priority
Needs Review
Priority
Next Meeting
Priority
🔥 URGENT 🔥
Priority
Waiting on Assignee
Priority
Waiting on External
Priority
Waiting on Reporter
rabbitmq
release-monitoring
releng
request-for-resources
s390x
security
SMTP
sprint-0
sprint-1
src.fp.o
staging
unfreeze
waiverdb
websites-general
wiki
Backlog Status
Needs Review
Backlog Status
Ready
chore
documentation
points
01
points
02
points
03
points
05
points
08
points
13
Priority
High
Priority
Low
Priority
Medium
Sprint Status
Blocked
Sprint Status
Done
Sprint Status
In Progress
Sprint Status
Review
Sprint Status
To Do
Technical Debt
Work Item
Bug
Work Item
Epic
Work Item
Spike
Work Item
Task
Work Item
User Story
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
infra/tickets#13464
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description of request
I want to request @jpodivin access to AWS.
Jiri Podivin is a member of the Logdetective team. He has been using an instance in EC2 as part of aws-copr. He did not need access to AWS as I spawned the machine for him and added him to the SSH access key.
Now he resolved that instead of using a standalone machine for interference, it would be easier and cheaper to use the AWS Bedrock service.
I created in AWS IAM the role aws-logdetective that has access to Bedrock, and is coupled to Fedora identity provider. But the next step is to configure FAS (if I understand it correctly) to allow usage of the aws role. And this is what I am unable to set up.
Can you please finish the configuration?
So, you want this to be a new aws-bedrock role with group, etc? If that then https://docs.fedoraproject.org/en-US/infra/sysadmin_sops/aws-access/#_adding_a_role_to_aws_iam is the process (needs a new fas group, ipsilon changes and aws changes)
Or did you just want existing aws-logdetective role to be able to use it? In that case you should be able to just add that iam policy to the existing aws-logdetective role?
@msuchy any thoughts on the above?
Sorry for the delay. I want the latter - the existing aws-logdetective role to be able to use.
But the aws-logdetective is something I created just moments before I created this ticket. So I will need to go though that SOP you linked (thank you for that).
I.e. can you please create the FAS group
aws-logdetectiveand make jpodivin member and sponsor of this group for a start?