Document explicit policy on granting BQ access to services
Categories
(Data Platform and Tools :: General, task, P3)
Tracking
(Not tracked)
People
(Reporter: klukas, Unassigned)
References
Details
(Whiteboard: [dataplatform])
Attachments
(1 file)
This bug is for tracking implementation of docs for our policies around granting Mozilla services access to specific tables in BigQuery, with special focus on policies around "live" data.
See the Access controls for services accessing BigQuery section of the proposal doc.
I am imagining that this end up on DTMO, but Data SRE may have suggestions for Mana content that should be updated to reflect this.
Comment 1•3 years ago
|
||
I created a data access workgroups doc, which covers a few cases where workgroups are used and includes this case: https://mana.mozilla.org/wiki/display/DOPS/Data+Access+Workgroups#DataAccessWorkgroups-Workgroupaccessforautomationandapplicationserviceaccounts. It's not as prescriptive as the proposal doc (which recommends specific views be created per application), it's meant mainly to indicate:
- service accounts shouldn't generally be granted
workgroup:mozilla-confidential
-level access to data - how to grant specific access to data
If you think this is sufficient documentation for this case then we can close this.
Comment 2•3 years ago
|
||
Reporter | ||
Comment 3•3 years ago
|
||
I do think this documentation is sufficient, but we should make sure we link to this documentation from bigquery-etl before closing this. Just linked a PR for this.
Reporter | ||
Updated•3 years ago
|
Updated•2 years ago
|
Description
•