Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

enterprise/compliance needs? #4722

Open
1 task done
rbtcollins opened this issue Sep 29, 2024 · 2 comments
Open
1 task done

enterprise/compliance needs? #4722

rbtcollins opened this issue Sep 29, 2024 · 2 comments
Labels
feature-request Requests for new features or capabilities linear Created by Linear-GitHub Sync

Comments

@rbtcollins
Copy link

Is this issue related to an issue?.

Apologies if I've missed it, but there doesn't seem to be any support for a range of features often needed in high governance environments.

There is 'Enterprise features
Custom authentication, ubiquitous access control, history, etc.' in the roadmap, but it isn't clear what the timeframe for that is.

The specific features I'm interested in are

a) those that prevent the (ab)use of a single compromised browser session (or laptop) from affecting a change to production, or exfiltrating a secret. For instance mandatory peer review before application, and before any dry run which might read-out secret material.

b) dealing with a fleet of similar infrastructure - we have many instances of a single basic infrastructure with some minor variance between them. This is currently managed in terraform by parameterising a root module with a unique state file + parameters that encompass the variation. Its also not clear whether this is (or isn't) on the roadmap today - it seems to be a different dimension of scale to me - one of managing complexity at a higher level than the component model; but perhaps components are the intended solution here?

Describe the outcome you'd like from us

For the governance question, just knowing if it is short-term, medium, or 'eventually' would be great!

For the other one, its more of a discussion, but discussions aren't turned on in Github, and discord isn't indexed, so no-one can learn from the discussion, so I guess we'll see if you'll take it here :).

Describe alternatives you've considered

Not having the feature isn't viable unfortunately. Maybe in a world with no threat actors.

Code of Conduct

  • I agree to follow this project's Code of Conduct

Additional context

No response

@rbtcollins rbtcollins added feature-request Requests for new features or capabilities linear Created by Linear-GitHub Sync labels Sep 29, 2024
@stack72
Copy link
Contributor

stack72 commented Oct 15, 2024

Hi @rbtcollins

Thanks for opening the issue here - my apologies it has taken us a while to get back to you. We have already started the work to have mandatory peer reviews - https://www.systeminit.com/blog/opportunity-rebac

The work for #2 is underway as well - https://www.systeminit.com/blog/opportunity-management-functions

There is another piece of work in the pipeline for an audit history and a blog post and video will come later this week on that

We expect these pieces of work to be available at the end of October - the blog posts note the specific details of what they will enable

Hope this helps

Paul

@stack72
Copy link
Contributor

stack72 commented Nov 25, 2024

Hi @rbtcollins

I'd like to follow up here to point out that our approval workflows are now live - https://www.systeminit.com/blog/announcing-approval-workflows

We are also very close to being able to deliver the management functions work - more on that next week (after the thanksgiving break!)

Paul

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature-request Requests for new features or capabilities linear Created by Linear-GitHub Sync
Projects
None yet
Development

No branches or pull requests

2 participants