Platform Access

The access management process for all Platform SSO enabled Services.

All Somebody provided SSO enabled Services are reachable via the Somebody Okta instance: https://somebody.okta-emea.com.

As all users are synced from the Urbandrive Okta to the Somebody Okta, can login to the Somebody Okta instance with your Urbandrive credentials.

Gaining Access to Platform Services

The access management has been completely automated and integrated into the usual on-boarding workflow.

When creating the usual on-boarding ticket in the Client-IT Service Desk, there are three new fields, which will determine the access to somebody systems:

  • Architectural Domain: multi-selection (rental, pricing, payment, fleet, ...)
  • Architectural Domain Watcher (WIP): multi-selection (rental, pricing, payment, fleet, ...)
  • Infrastructure Access: boolean (Yes, No)

Access to all Somebody systems is determined based on these values.

Permissions Changes to Somebody Services can also be requested via the Permission Change ticket in the Somebody Service Desk.

⚠️ Tickets are processed automatically and will always be assigned to the ticket reporter. Therefor Permissions can not be requested on behalf of someone else

⚠️ Permissions specified in the ticket are not additive, please always specify ALL required permissions, otherwise existing permissions will be lost

Authentication Matrix

Infrastructure AccessDomains AssignedDomain Watcher Grants Access to Additional DomainsAccess to System AllowedHint
No0None
Yes0 or moreAWS VPN (Aviatrix VPN)
Yes0 or moreKibana
Yes0 or morePrometheus Stack
Yes0 or moreGitlabpermissions inside of gitlab must be assigned manually ( owner of group/repo ) is responsible
Yes0 or more1password
Yes1 or moreAWS Console + CLI
Yes1 or moreAWS EKS
Yes1 or moreArtifactory
Yes1 or morecloudamqppermissions inside of cloudamqp must be granted manually
Yes1 or moreSentrypermissions inside of Sentry must be assigned manually
Yes1 or moreAtlas / Mongodb

Authorization inside Platform Provided Services

The authorization inside a specific service depends on the respective service and the Product Group / Infrastructure attributes, which are explained here:

AWS Console + CLI

All users authenticated to AWS will get access to the AWS accounts matching their assigned Product Groups. More details on what roles are granted inside an AWS account can be found here: AWS SSO and IAM Architecture.

AWS VPN (Aviatrix)

After getting the approval from the ServiceDesk ticket, at a max of 30 minutes (from 9-to-5), the user will get the email from Aviatrix VPN for instructions on how to get access.

Gitlab

All authenticated users start with no Gitlab groups assigned and therefor can only see projects with "internal" visibility (default for new projects). Gitlab groups related to different architectural domains are managed by the chapter leads of the matching domains manually inside Gitlab. For more information take a look at the official docs.

Artifactory

All users authenticated Artifactory will get read/write access to local repositories of their product Group and read access to remote ones. The Chapter leads will have Admin permissions and can create local/virtual repositories.

Programmatic access from the pipeline can be configured individually via Access Tokens.

In case of problems, please refer to this doc: https://urbandrive.atlassian.net/wiki/spaces/Platform/pages/348225784/JFrog+Artifactory%3A+programmatic+access+from+pipeline.

1 Password

Okta does not provide SSO for 1password, but the automatic usermanagement and vault assignement is done here. To setup your account follow these steps:

  • click on the link in the invitation email (not in the webui)
  • create your master password
  • securely store your recovery document (SECRET KEY)
  • open the menu in the top right corner and get the apps
  • download and install the latest version
  • go back to the 1password webpage and click add your account directly

Background Information

So why another Okta Instance? This enables us to add more applications to Okta faster, by not relying on handover to the Client-IT chapter, which will increase our velocity significantly.

This Somebody Okta instance is an Okta sub-instance of the Client-IT provided https://urbandrive.okta-emea.com instance. Further details on the implementation can be found here: Single Sign On for Infrastructure Services