fivexl/terraform-aws-sso-elevator
Slack bot to temporary assign AWS SSO Permission set to a user
PythonApache-2.0
Issues
- 5
Limitation of request to lambda from internet
#93 opened by oleksandrsv - 3
- 0
Handle `AccessDeniedException` while creating permission set for management account, and update documentation about access to management account
#101 opened by EreminAnton - 0
Consider creating a set of SCP's that will prohibit change of the SSO Elevator's resources
#100 opened by EreminAnton - 0
Code review fixes
#94 opened by EreminAnton - 0
Potential Feature: Create a CLI command for the requester, so the user can copy and paste it instead of filling out the form.
#99 opened by EreminAnton - 0
We can add more information to the audit entry by logging details about incomplete and declined requests.
#98 opened by EreminAnton - 0
Consider making the group request more informative. Include a description of the SSO group, the names of the policies it has, and the accounts assigned to it.
#97 opened by EreminAnton - 0
Retrieve the group IDs from the group_config and use them to specify IAM policies for the Lambda functions.
#96 opened by EreminAnton - 0
1.4.0 Release
#92 opened by EreminAnton - 0
Fix failing localstak
#89 opened by EreminAnton - 4
- 6
Terraform Cloud
#75 opened by dash-aug - 1
Fix initial CodeGuru findings
#73 opened by Andrey9kin - 2
SecurityHub is unhappy with Lambda URL
#81 opened by Andrey9kin - 2
Rename variables in nex major release
#49 opened by EreminAnton - 0
Codereview fixes
#88 opened by EreminAnton - 0
Deprecate Lambda url usage
#91 opened by EreminAnton - 0
Consider setuping WAF for the API Gateway
#90 opened by EreminAnton - 0
- 0
Cleaning cache problem
#86 opened by EreminAnton - 0
- 0
Consider using https://api.slack.com/distribution to simplify the distribution
#84 opened by EreminAnton - 0
Create a "deployed in delegated SSO admin account" flag for Elevator, so Elevator will conditionally prohibit the creation of account assignments for the management account (because they fail with errors).
#83 opened by EreminAnton - 0
- 0
If a request for access is set for 24 hours, then the request will work as 0h instead of 24.
#62 opened by EreminAnton - 1
Check if slack signing secret works in sso elevator, cant we acces our lambda with url from other app?
#67 opened by EreminAnton - 0
Color-coding for requests
#45 opened by Andrey9kin - 0
- 0
Refactoring temporary access logic
#66 opened by EreminAnton - 0
Social media previev
#72 opened by EreminAnton - 0
OCSF Schema format supprot
#71 opened by EreminAnton - 0
- 2
Session termination for revoking access
#54 opened by EreminAnton - 4
- 3
Integration with MS Teams
#60 opened by oleksandrsv - 0
- 2
- 0
Make the dead_letter SNS topic optional.
#55 opened by EreminAnton - 2
- 1
Enable dependabot
#44 opened by Andrey9kin - 0
- 0
- 0
SSO Elevator. Users click "Approve" button in the same moment. Second user got an error, but we create two revoke schedulers
#47 opened by EreminAnton - 0
- 0
- 1
replace CI with re-usable workflows
#43 opened by Andrey9kin - 1
Add message to expired event
#42 opened by EreminAnton - 0
- 0
Update wording of consistency checker - make it clear that if no action is taken un-identified assignment will be revoked. Specify when if possible. No need to mention checking logs
#39 opened by Andrey9kin