| 7 Oct 2025 |
hexa | djacu: What is the idea behind infra managing that account? | 11:42:38 |
hexa | not that I'd be opposed, just wondering | 11:42:48 |
djacu | In reply to @hexa:lossy.network not that I'd be opposed, just wondering Honestly I don't know what the process is for creating accounts. I thought this was an Infrastructure Team responsibility since you all provided the Vault Warden account.
Could the Marketing Team create the account, add it to the vault, and if other teams need access in the future then it gets shared? | 15:38:41 |
hexa | yep | 15:38:56 |
djacu | In reply to @tgerbet:matrix.org
I have the control of the nixos and nixpkgs orgs on npmjs.com due to some security incident handling in the past (someone had reserved yarn2nix name which could have lead to some dependency confusion...)
I'm fine with adding members of a team to it and dropping my access afterwards That last part was more hypothetical for the future accounts. This sounds like the way to go. @tgerbet:matrix.org: I'll ask @avocadoom to reach out and work with you to do the hand off | 15:42:10 |
Jonas Chevalier | The most important thing after adding shared secrets to Vault is to document who owns what in https://github.com/nixos/org . If you don't find the right place, the structure needs to be expanded. | 16:03:42 |
Jonas Chevalier | That way we can know who to talk to | 16:04:26 |
| @blastboomstrice:4d2.org joined the room. | 18:54:48 |