4 ms·
We have some "shared" users for things like bots, etc.. wonder how to deal with that since we don't want to enable MFA for them. Otherwise I'd be all over this.
by mwarkentin 10y ago
We have some "shared" users for things like bots, etc.. wonder how to deal with that since we don't want to enable MFA for them. Otherwise I'd be all over this..
- RyJones 10y agoThis is a huge issue for us at the Linux Foundation. Infra accounts make enforcing MFA for orgs impossible Even if I could do classes of accounts. Owners and admins, MFA required. Users (bots) that just update CI status, not required.
- sciurus 10y agoFor CI bots I think in the future you will be able to build an "integration" instead of using a user account. From the blog post "We’re rethinking our integrations model to provide better ways for tools to extend and integrate with GitHub. We’ve added the ability for an integration to act on its own behalf instead of impersonating a user—making it a first class actor on GitHub without using a paid seat. Admins will have the ability to configure integrations directly on Organizations and control which repositories they allow access to." https://developer.github.com/changes/2016-09-14-Integrations-Early-Access/ https://developer.github.com/changes/2016-09-14-Integrations... https://developer.github.com/early-access/integrations/ https://developer.github.com/early-access/integrations/
- WorldMaker 10y agoAlso mentioned in the announcement is that bots and integrations won't need their own user accounts or to impersonate users in the (near?) future.
- gregshap 10y agoFor bot accounts, you either generate a personal access token for that account or (probably better) use SSH. Not so different from human users who have 2FA activated and use the command line to interact with github. https://help.github.com/articles/providing-your-2fa-authentication-code/ https://help.github.com/articles/providing-your-2fa-authenti...