lahirujayathilake opened a new pull request, #578:
URL: https://github.com/apache/airavata-custos/pull/578

   No cluster account is created automatically. A cluster user now waits until 
an admin approves it. Approving starts provisioning, denying stops it, both go 
to the audit log.
   
   **Flow**
   
   AMIE packet
     -> cluster user row (approval_status = `PENDING`)
     -> `compute_cluster_user::create`        (published, nobody listens now)
   
   admin approves
     -> row `APPROVED`, `reviewed_by`, `reviewed_at`
     -> audit `CLUSTER_ACCOUNT_APPROVED`
     -> `compute_cluster_user::approve`       (new event)
     -> registry connector provisions the account, same handler as before
   
   admin denies
     -> row `DENIED`, `reviewed_by`, `reviewed_at`, `review_note`
     -> audit `CLUSTER_ACCOUNT_DENIED`
     -> no event, nothing is created on the cluster
   
   **Events**
   
   - New: `compute_cluster_user::approve`. The registry connector subscribes to 
this instead of `::create`.
   - `compute_cluster_user::create` is still published on every create but has 
no subscriber.
   - A cluster user an admin directly adds (onboarding flow) is approved at 
creation and publishes both `::create` and `::approve` events.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to