lahirujayathilake opened a new pull request, #578:
URL: https://github.com/apache/airavata-custos/pull/578
No cluster account is created automatically. A cluster user now waits until
an admin approves it. Approving starts provisioning, denying stops it, both go
to the audit log.
**Flow**
AMIE packet
-> cluster user row (approval_status = `PENDING`)
-> `compute_cluster_user::create` (published, nobody listens now)
admin approves
-> row `APPROVED`, `reviewed_by`, `reviewed_at`
-> audit `CLUSTER_ACCOUNT_APPROVED`
-> `compute_cluster_user::approve` (new event)
-> registry connector provisions the account, same handler as before
admin denies
-> row `DENIED`, `reviewed_by`, `reviewed_at`, `review_note`
-> audit `CLUSTER_ACCOUNT_DENIED`
-> no event, nothing is created on the cluster
**Events**
- New: `compute_cluster_user::approve`. The registry connector subscribes to
this instead of `::create`.
- `compute_cluster_user::create` is still published on every create but has
no subscriber.
- A cluster user an admin directly adds (onboarding flow) is approved at
creation and publishes both `::create` and `::approve` events.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]