Skip to content

[Feature Request] Set Essential Contacts Domain Allow-List via Org Policy YAML #92

@Jberlinsky

Description

@Jberlinsky

Feature Description

Allow the essentialcontacts.managed.allowedContactDomains allow-list to be set via fast/stages-aw/0-bootstrap/data/custom-org-policies/platform_policy.yaml

Use Case

The Security Best Practice guide strongly suggests making changes to the Essential Contacts Domain Allow-List Org Policy via IaC. Stellar Engine presently will not accept such changes.

Proposed Solution

Accept the parameters argument to managed org-policies via their YAML definition and pass it through to the org policy TF resources.

Compliance & Deployment Context

  • Target Deployment Type(s):
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Medium
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • All / General
  • Relevant NIST 800-53r5 Controls: (If applicable, list the controls this feature helps satisfy)

Reusability Check

Stellar Engine prioritizes reusability.

  • I have checked if this functionality can be achieved by extending an existing module or blueprint.
  • I have verified that this does not duplicate existing functionality.

Alternatives Considered

The current alternative is to update the Security Best Practice Guide to accurately (with respect to the state of the repository presently) reflect that this update would be made via click-ops.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions