Skip to content

Commit

Permalink
docs: Fix link to handbook. Clarify that developers only get access t…
Browse files Browse the repository at this point in the history
…o development servers, not production servers
  • Loading branch information
jpmckinney committed Apr 15, 2024
1 parent 46acc51 commit 9915e88
Showing 1 changed file with 4 additions and 4 deletions.
8 changes: 4 additions & 4 deletions docs/reference/index.rst
Original file line number Diff line number Diff line change
Expand Up @@ -73,25 +73,25 @@ Administrative access

.. seealso::

`Software Development Handbook <https://ocdsdeploy.readthedocs.io/en/latest/reference/index.html>`__, for access to third-party services
`Software Development Handbook <https://ocp-software-handbook.readthedocs.io/en/latest/services/admin.html>`__, for access to third-party services

The staff of the following organizations have had administrative roles:

- `Open Contracting Partnership <https://www.open-contracting.org/about/team/>`__ (OCP)
- `Dogsbody Technology <https://www.dogsbody.com>`__
- `RBC Group <https://www.rbcgrp.com>`__

The ``ssh.root`` lists in Pillar files and the ``ssh.admin`` list in the ``pillar/common.sls`` file give people access to servers. All people should belong to the above organizations.

.. _root-access-policy:

Root access
~~~~~~~~~~~

Server owners (OCP) and server managers (Dogsbody for Linux, RBC for Windows) should have root access. Otherwise, only developers who are reasonably expected to deploy to a server should have root access to that server; anyone with root access can grant that developer root access.
Server owners (OCP) and server managers (Dogsbody for Linux, RBC for Windows) should have root access. Otherwise, only developers who are reasonably expected to deploy to a **development server** should have root access to that server; anyone with root access can grant that developer root access.

Root access should be :ref:`routinely reviewed<review-root-access>`. If a developer did not deploy (and was not granted root access) to a server within the last six months, their root access to that server should be revoked.

The ``ssh.root`` lists in Pillar files and the ``ssh.admin`` list in the ``pillar/common.sls`` file give people access to servers. All people should belong to the above organizations.

Redash
~~~~~~

Expand Down

0 comments on commit 9915e88

Please sign in to comment.