standards icon indicating copy to clipboard operation
standards copied to clipboard

Alerting Operators about non-compliance with SCS standards

Open itrich opened this issue 2 years ago • 1 comments

Operators,

we now have this nice new CI workflow that regularly checks all configured clouds against our SCS standards. It may happen that a cloud environment becomes (for any reason) noncompliant with our standards. How would you like to get informed about failing workflows. I see various possibilities:

  • A issue is generated for every noncompliant cloud and the issue is assigned to a nominated employee.
  • A mail is sent out to the operator.
  • You simply hook yourself to the workflow API and integrate this into your own alerting system.

What would you prefer, @frosty-geek @costelter @jnull @matfechner?

itrich avatar Feb 20 '23 07:02 itrich

FTR, as this issue has been discussed elsewhere, IMHO, this is an issue for SIG Standardization & Certification to tackle. If a certain level of certification requires a CSP to be compliant and the continuous integration (CI) workflow shows that it is not the case, the certification may be lost.

Hence, I think that for now, while we're still in the MVP phase, the primary way would be to use the approach of saying, "Hey, this looks broken. Have you had a chance to take a look at it?"

frosty-geek avatar Feb 20 '23 21:02 frosty-geek