TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Determining IaC ownership – a tag-based approach

5 点作者 marsh_mellow大约 1 个月前

4 条评论

Take8435大约 1 个月前
This is just adding metadata. The whole blog can be reduced to...<p>&#x27;Tag resources for any cloud you work in&#x27;<p>Azure recommends this. AWS recommends this. etc.<p><a href="https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;whitepapers&#x2F;latest&#x2F;tagging-best-practices&#x2F;what-are-tags.html" rel="nofollow">https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;whitepapers&#x2F;latest&#x2F;tagging-best-...</a> <a href="https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;azure&#x2F;azure-resource-manager&#x2F;management&#x2F;tag-resources" rel="nofollow">https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;azure&#x2F;azure-resource-manag...</a>
评论 #43632612 未加载
tikkabhuna大约 1 个月前
I&#x27;ve never considered ownership in an IaC repo down to the individual resource and I&#x27;m struggling to see the usecase.<p>We also use tags&#x2F;labels to link the generated &quot;thing&quot; back to the repository that created it with:<p>- The repo URL<p>- The pipeline URL<p>- The commit hash (also retrievable from the pipeline details)<p>These are all discovered via GitLab CI variables [1].<p>From this we would use the Git repository to identify ownership. We have the benefit of our Infosec team having wide access to our GitLab instance, which might hamper other companies.<p>How would you handle a situation where someone creates a resource but then leaves?<p>The good thing about looking at an entire repository is that it gives you the entire history and who else might have worked on it. In hierarchical Git providers (eg. GitLab), it can also indicate where the project sits relative to others. If you just have a single person, you may struggle to find out who now owns a resource.<p>[1] <a href="https:&#x2F;&#x2F;docs.gitlab.com&#x2F;ci&#x2F;variables&#x2F;predefined_variables&#x2F;" rel="nofollow">https:&#x2F;&#x2F;docs.gitlab.com&#x2F;ci&#x2F;variables&#x2F;predefined_variables&#x2F;</a>
easton大约 1 个月前
NHI =&gt; Non-human identity, something I had never heard before reading this (even though i was familiar with the concept of identities for services, like service accounts or iam roles or whatever). I wonder if that&#x27;s a common acronym.
评论 #43632001 未加载
moribvndvs大约 1 个月前
This was borderline incoherent.