Thomas Strömberg 🚲🌳🛵<p>Our latest <a href="https://triangletoot.party/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> drop: <a href="https://github.com/chainguard-dev/acls-in-yaml" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/chainguard-dev/acls</span><span class="invisible">-in-yaml</span></a></p><p>As part of <a href="https://triangletoot.party/tags/SOC2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOC2</span></a> <a href="https://triangletoot.party/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a>, we've been using this to run monthly <a href="https://triangletoot.party/tags/audit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>audit</span></a> reviews of our ACLs across SaaS platforms: <a href="https://triangletoot.party/tags/GCP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GCP</span></a>, <a href="https://triangletoot.party/tags/Slack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Slack</span></a>, <a href="https://triangletoot.party/tags/Vercel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vercel</span></a>, etc. </p><p>acls-in-yaml dumps <a href="https://triangletoot.party/tags/ACLs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ACLs</span></a> from each platform into a consistent and neutral <a href="https://triangletoot.party/tags/YAML" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>YAML</span></a> format, which makes it easy to visualize change over time. </p><p>We use this by committing the result into a <a href="https://triangletoot.party/tags/Github" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Github</span></a> repo and getting the PR reviewed by the admins for each system.</p><p>PS: ACL change alerts are also awesome!</p>