Platform Access
The access management process for all Platform SSO enabled Services.
All Somebody provided SSO enabled Services are reachable via the Somebody Okta instance: https://somebody.okta-emea.com.
As all users are synced from the Urbandrive Okta to the Somebody Okta, can login to the Somebody Okta instance with your Urbandrive credentials.
Gaining Access to Platform Services
The access management has been completely automated and integrated into the usual on-boarding workflow.
When creating the usual on-boarding ticket in the Client-IT Service Desk, there are three new fields, which will determine the access to somebody systems:
Architectural Domain: multi-selection (rental, pricing, payment, fleet, ...)Architectural Domain Watcher(WIP): multi-selection (rental, pricing, payment, fleet, ...)Infrastructure Access: boolean (Yes, No)
Access to all Somebody systems is determined based on these values.
Permissions Changes to Somebody Services can also be requested via the Permission Change ticket in the Somebody Service Desk.
⚠️ Tickets are processed automatically and will always be assigned to the ticket reporter. Therefor Permissions can not be requested on behalf of someone else
⚠️ Permissions specified in the ticket are not additive, please always specify ALL required permissions, otherwise existing permissions will be lost
Authentication Matrix
| Infrastructure Access | Domains Assigned | Domain Watcher Grants Access to Additional Domains | Access to System Allowed | Hint |
| No | 0 | None | ||
| Yes | 0 or more | AWS VPN (Aviatrix VPN) | ||
| Yes | 0 or more | ✅ | Kibana | |
| Yes | 0 or more | ✅ | Prometheus Stack | |
| Yes | 0 or more | Gitlab | permissions inside of gitlab must be assigned manually ( owner of group/repo ) is responsible | |
| Yes | 0 or more | 1password | ||
| Yes | 1 or more | AWS Console + CLI | ||
| Yes | 1 or more | AWS EKS | ||
| Yes | 1 or more | Artifactory | ||
| Yes | 1 or more | cloudamqp | permissions inside of cloudamqp must be granted manually | |
| Yes | 1 or more | Sentry | permissions inside of Sentry must be assigned manually | |
| Yes | 1 or more | Atlas / Mongodb |
Authorization inside Platform Provided Services
The authorization inside a specific service depends on the respective service and the Product Group / Infrastructure attributes, which are explained here:
AWS Console + CLI
All users authenticated to AWS will get access to the AWS accounts matching their assigned Product Groups. More details on what roles are granted inside an AWS account can be found here: AWS SSO and IAM Architecture.
AWS VPN (Aviatrix)
After getting the approval from the ServiceDesk ticket, at a max of 30 minutes (from 9-to-5), the user will get the email from Aviatrix VPN for instructions on how to get access.
Gitlab
All authenticated users start with no Gitlab groups assigned and therefor can only see projects with "internal" visibility (default for new projects). Gitlab groups related to different architectural domains are managed by the chapter leads of the matching domains manually inside Gitlab. For more information take a look at the official docs.
Artifactory
All users authenticated Artifactory will get read/write access to local repositories of their product Group and read access to remote ones. The Chapter leads will have Admin permissions and can create local/virtual repositories.
Programmatic access from the pipeline can be configured individually via Access Tokens.
In case of problems, please refer to this doc: https://urbandrive.atlassian.net/wiki/spaces/Platform/pages/348225784/JFrog+Artifactory%3A+programmatic+access+from+pipeline.
1 Password
Okta does not provide SSO for 1password, but the automatic usermanagement and vault assignement is done here. To setup your account follow these steps:
- click on the link in the invitation email (not in the webui)
- create your master password
- securely store your recovery document (SECRET KEY)
- open the menu in the top right corner and get the apps
- download and install the latest version
- go back to the 1password webpage and click add your account directly
Background Information
So why another Okta Instance? This enables us to add more applications to Okta faster, by not relying on handover to the Client-IT chapter, which will increase our velocity significantly.
This Somebody Okta instance is an Okta sub-instance of the Client-IT provided https://urbandrive.okta-emea.com instance. Further details on the implementation can be found here: Single Sign On for Infrastructure Services