Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bot account for shared credentials #615

Closed
zowoq opened this issue Jun 2, 2023 · 9 comments
Closed

bot account for shared credentials #615

zowoq opened this issue Jun 2, 2023 · 9 comments

Comments

@zowoq
Copy link
Contributor

zowoq commented Jun 2, 2023

Currently some tokens are linked to admins accounts, e.g. GANDI_KEY.

@zowoq
Copy link
Contributor Author

zowoq commented Aug 16, 2023

@Mic92 @zimbatm

I was going to add admin@nix-community as a user to the gandi account for this token but using an gandi email alias to manage the gandi account seems a bit awkward.

Should we have a separate, real email account we can use for this stuff (cloudflare superadmin, gandi, etc) and forward that to the admins as well?

@zimbatm
Copy link
Member

zimbatm commented Aug 17, 2023

good idea 👍

@zowoq
Copy link
Contributor Author

zowoq commented Aug 18, 2023

Any preferences on which service to use? Might just use gmail?

@Mic92
Copy link
Member

Mic92 commented Sep 19, 2023

no preference

@zimbatm
Copy link
Member

zimbatm commented Sep 20, 2023

I would just add a forwarding address mybotaccount@nix-community.org -> admin@community.org, and then use that to create the bot account. As long as we control the whole chain it's fine.

@zowoq
Copy link
Contributor Author

zowoq commented Sep 20, 2023

I would just add a forwarding address mybotaccount@nix-community.org -> admin@community.org, and then use that to create the bot account. As long as we control the whole chain it's fine.

I don't understand how using two aliases like this is different from using one alias?

@Mic92
Copy link
Member

Mic92 commented Sep 20, 2023

Yeah we need a domain that is not controlled by the registrar that we are trying to login to avoid dependency cycles.

@zowoq
Copy link
Contributor Author

zowoq commented Oct 26, 2023

https://api.gandi.net/docs/authentication/

Gandi api keys are deprecated and have been replaced by personal access tokens. The terraform provider doesn't support tokens yet so I'll leave this until it does.

@zowoq
Copy link
Contributor Author

zowoq commented Jan 11, 2024

I thought that we had another token linked to an admins account but I can't see one in the secrets.

Closing as this seems it was only an issue with gandi.

@zowoq zowoq closed this as completed Jan 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants