Security¶
Requesting Access¶
Credentials are in Vault at vault kv get secret/rubin/minor-planet-survey/postgres
rubin
is setup as the general user account. rubin_rw
is setup with right permissions. It was requested to be able to update values for testing. Grants are managed in grants.sql in the GitHub Repository
Service accounts¶
No Kubernetes Service Accounts.
The epo
user is setup as the replication user for EPO.
Security Incident Response¶
The main risk is that the replication password is compromised. If the password is compromised contact the Minor Planet Center Annex and to reset the password.