Remove relay SAS keys - #164
Conversation
steventux
left a comment
There was a problem hiding this comment.
We're missing a description of the intent of this PR, also JIRA links help us track the changes.
I've suggested a couple of things for readability and formatting.
2a153d9 to
b0278d7
Compare
5ce20af to
55ebe46
Compare
91c0c0a to
b025d0c
Compare
b025d0c to
13ad7cb
Compare
steventux
left a comment
There was a problem hiding this comment.
Could do with fixing up or deleting the wip commit. The SAS key descriptions refer to Arc machines which might be confusing.
Otheriwise looks good.
8bc20e0 to
1ea2923
Compare
All deployed environments must use managed identities for security reasons. For authenticating both the web application and the gateways.
8ab004e to
e9d76d8
Compare
steventux
left a comment
There was a problem hiding this comment.
Looks good to me. One question about removing the listen hybrid connection.
It might be handy to have this in place on the review env only.
b633708 to
e9d76d8
Compare
|
As discussed with @steventux, these SAS keys were only created for the ARC registered gateways. These machines already use managed identities. |
Description
Remove Azure Relay SAS keys
All deployed environments now authenticate to Azure Relay using Managed Identity, so retaining SAS keys increases attack surface.
Jira link
https://nhsd-jira.digital.nhs.uk/browse/DTOSS-13123
Review notes
Review checklist