Skip to content

Commit 1366d5e

Browse files
rkosterbeyhan
andauthored
[RFC] Administrative Access to CFF Infrastructure (#1415)
* Create rfc-draft-toc-admin-access-to-foundation-accounts.md * Add Slack --------- Co-authored-by: Beyhan Veli <beyhan.veli@sap.com>
1 parent 0bb1ada commit 1366d5e

1 file changed

Lines changed: 29 additions & 0 deletions

File tree

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
2+
# Meta
3+
[meta]: #meta
4+
- Name: TOC Administrative Access to CFF Infrastructure
5+
- Start Date: 2026-01-27
6+
- Author(s): @rkoster
7+
- Status: Draft
8+
- RFC Pull Request: (fill in after submission)
9+
10+
## Summary
11+
12+
This RFC proposes granting all Technical Oversight Committee (TOC) members admin-level access to key Cloud Foundry Foundation (CFF) infrastructure systems, including Concourse instances, Docker Hub organizations, Cloudflare, and all IaaS accounts used by the CFF. The goal is to improve responsiveness and reduce operational bottlenecks.
13+
14+
## Problem
15+
16+
TOC members are responsible for the technical oversight of Cloud Foundry but currently lack the permissions required to assist engineers when issues arise within critical CFF-managed accounts. This creates delays—especially across time zones—when troubleshooting CI outages, image publishing failures, DNS/CDN issues, or IaaS‑level infrastructure problems. Access is currently limited to a few individuals, creating single points of failure.
17+
18+
## Proposal
19+
20+
TOC members SHOULD be granted full administrative access to:
21+
- All CFF-managed Concourse CI instances
22+
- CFF Docker Hub organizations
23+
- The Cloudflare CFF account
24+
- All IaaS provider accounts used by the CFF
25+
- CF community Slack workspace
26+
27+
This access MUST be provisioned through existing secure authentication methods (e.g., SSO, MFA) and MUST remain auditable. When TOC membership changes, access MUST be updated immediately.
28+
29+
Providing TOC members with this level of access WILL enable timely support for engineering teams globally, reduce dependency on a small number of privileged account holders, and strengthen operational resilience.

0 commit comments

Comments
 (0)