lahirujayathilake opened a new pull request, #545:
URL: https://github.com/apache/airavata-custos/pull/545

   Users got cluster access when added to an allocation, but never lost it. 
Deactivating a member, removing them, or deactivating the allocation left them 
able to keep submitting jobs. The events for all of this were already being 
published, but nothing was listening to them.
   
   ## What this does
   
   - Deactivating or deleting a membership removes that member's access to that 
 allocation, and nothing else.
   - Deactivating or deleting an allocation removes access for all of its 
members.
   - Reactivating either one restores access.
   
   ## Background check
   
   The reconciler added in https://github.com/apache/airavata-custos/pull/544 
only filled in missing access. It now also removes access that is no longer 
granted, so a missed event cannot leave someone with access forever.
   
   Removing access is riskier than granting it, so the reconciler does nothing 
when it is unsure. It skips removal if no one on the cluster appears to have 
access (far more likely a failed lookup than a genuinely empty cluster), if a 
lookup it depends on fails, or if the account is not one Custos manages. It 
also leaves alone an allocation's own limits and members whose accounts were 
only just created.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to