4 ms·
The lack of ACLs or comparable permissions is by far the biggest thing that prevents me from recommending DO for production workloads. This kind of thing is abs
by turtles3 3y ago
The lack of ACLs or comparable permissions is by far the biggest thing that prevents me from recommending DO for production workloads. This kind of thing is absolutely essential. You can't even separate dev resources from prod resources, every API key has godmode on your whole account. This is a security disaster.
For a simple example, I'm running externaldns on a kubernetes cluster. For production use, I'd want to at least have an API key that can only access the DNS domains and nothing else. As is, the key can create compute resources or delete anything (including object storage buckets!). Again with no dev/prod isolation, so a leaked dev key that looks innocuous means your prod resources are now compromised.
Some second tier providers do better at this, OVH and scaleway both have some concept of ACLs, but DO just don't even try.
Apologies for the slight rant but it's frustrating to see something so basic overlooked by a company the size of DO.
- csnweb 3y agoI agree, probably the biggest point Digitalocean is lacking. I think the only workaround is creating several projects? But that probably becomes annoying and hard to manage quite easily if you want a lot of separation.
- deleted 3y ago[deleted]
- turtles3 3y agoIIRC projects only group resources under the same account. API keys are still account-wide, so projects provide no isolation there. There is a other mechanism DO has to allow multiple accounts under one billing context (I think it might be called 'teams'?) but sadly this is still extremely coarse grained, and doesn't allow you to lock a key down to a particular resource, or even a class of resources.
- unilynx 3y agoTeams have separate billing per team. Other platforms would call them ‘organization’
- juxhindb 3y agoAgreed. We had solved it at PhishDeck back in the day through the use of multiple projects, i.e., Platform Production, Platform Staging, Tooling Production, Tooling Staging etc. Still not ideal, but it minimised security risk and kept things organised.
- tigeroil 3y agoYou've described exactly why my company moved from DigitalOcean to AWS a while ago. Whilst AWS is more expensive and perhaps over-engineered for our use-case, it was absolutely essential to have some kind of ACLs. I mean, I can't exactly give my junior dev access to DO if it means he can also delete the entire production database and all backups with a misclick.