Re: I'm enabling topic authorization on the production bus

2023-07-10 Thread Ben Cotton
On Mon, Jul 10, 2023 at 11:44 AM Aurelien Bompard wrote: > > All the other accounts are only allowed to send to the topics they have > defined in Ansible. > This opens the door to letting external services publish to our message bus, > since we can make sure they can only publish to their

Re: Fedora infra for Secure Boot components - local setup

2023-07-10 Thread Kevin Fenzi
On Thu, Jul 06, 2023 at 02:18:04PM -, Kamil Aronowski wrote: > Thanks for the reply, Kevin. It means a lot to me, as I no longer feel alone > with this issue. I'll try the mock configuration later on, so I do not > overcomplicate things right now - once a basic config works for me, I'll then

Re: I'm enabling topic authorization on the production bus

2023-07-10 Thread Kevin Fenzi
Thanks for driving this forward! kevin signature.asc Description: PGP signature ___ infrastructure mailing list -- infrastructure@lists.fedoraproject.org To unsubscribe send an email to infrastructure-le...@lists.fedoraproject.org Fedora Code of

Re: I'm enabling topic authorization on the production bus

2023-07-10 Thread Aurelien Bompard
Done. The following users are not protected by ACLs (which means they can send to any topics): - notifs-web and notifs-backend, because we'll remove the old FMN soonish - alt-src: I couldn't contact the owner (Siteshwar?). Related to CentOS Stream. I tried to contact Brian Stinston. - coreos: