Adi: New User
All accounts created with aholadigital.com account unless otherwise specified.
- Create attracs.net account in admin.google.com
- OU:attracs for aholadigital personel
- OU:subcontractors for subcontractor personel
- Add user to groups to access GCP and limit with CAA
- Admins : gcp-organization-admins (admin permissions + CAA:GCP_CAA_policy)
- Everyone else : gcp-organization-users (CAA:GCP_CAA_policy_users only, usually use g_developer@attracs.net to give out permissions when needed)
- Add user to groups:
- Devops: g_devops
- Developers: g_developer
- Add access to databases (https://github.com/Attracs/attracs-linux-playbooks/tree/master/gcp/database_access)
- devops:
- pg: create admin (readwrite) user and make sure audit logging is on (attracs-linux-playbooks)
- others:
- If they can have access, create readonly user (attracs-linux-playbooks) (not usually needed)
- devops:
- Request attracs.com account from Ahola for AholaDigital own personel (Toni)
- Invite to Slack
- Invite to Everhour
- Invite to Clickup
- Invite to Github with personal account
- Invite to npmjs if needed (developers)
- Upload device serial number to Company Devices in google Workspace
- Invite to 1password if needed (only devops)
- Add to necessary vaults
- Invite to manage (nightly)
- add/invite to attracs org:
- add to developers team:
- devops: make superadmin
- In this link you can search users and add superuser to them from dropdown menu next to user. https://manage-nightly.attracs.com/admin#users
-
For devops, create an admin-user in online.local environment
-
Invite to Managevisor-nightly
- Update list of users in: https://github.com/Attracs/attracs-linux-playbooks/blob/master/services/managevisor/configs/attracs.yml
- Run
ansible-playbook managevisor.yml --vault-password-file=.vault_password_file
Remove
- Delete aholadigital.com account
- Request removal of attracs.com account from Ahola
- Delete Slack account
- Deactivate Everhour account
- Remove clickup user
- Remove from Github organization
- Remove from forestry.io if needed
- Remove devices from Google Workspace, from company inventory and accepted devices
- remove npmjs
- Personal Sendgrid api keys
- superset access
- remove account from manage
- remove account from auth0
- remove account from supportbee
- remove from managevisor
- remove from 1password
- remove from online.local domain