{"thread":{"id":"52492","subject":"IaC monitoring with Git","startedAt":"2019-12-19T21:30:28Z","lastAt":"2019-12-20T09:30:05Z","messageCount":2,"participants":["Christopher Díaz Riveros","Christian Couder"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"388577","messageId":"CAHCo6soNwee3hN4i6v0KtxphKHa96v--e41KRqfHKV5i45OqcA@mail.gmail.com","threadId":"52492","inReplyTo":null,"subject":"IaC monitoring with Git","fromName":"Christopher Díaz Riveros","fromEmail":"christopher.diaz.riv@gmail.com","sentAt":"2019-12-19T21:30:15Z","receivedAt":"2019-12-19T21:30:28Z","isPatch":false,"sender":{"key":"christopher.diaz.riv@gmail.com","avatar":"https://avatars.githubusercontent.com/u/14809105?v=4"},"body":"Hi all,\n\nI'm trying to figure out a git based solution for a use case we have\nat my work place. We use IaC for our infrastructure, when we want to\ncreate new instances/accounts/etc we add a certain set of tags in our\nfiles to indicate some key aspects of the instances/accounts.\n\nThere is one specific tag, owner, which we use to set a contact point\nin case we need someone to make a change. The main issue with this is\nthat you can set the tag to anything, valid or not, or it could become\ninvalid over time.\n\nWould a valid approach for first issue be to set a pre-receive hook in\nour repositories so that before the PR is merged, we check validity of\nthe contact email, a.k.a. owner tag (we assume validity means that\nemail exist), maybe via ldapsearch or another command like this?\n\nFor the second case, I'd assume git does not by default monitor\ncontents of files on a regular basis, does anybody have faced this\nissue and successfully found a way to periodically check contents and\ntrigger alerts on repositories based on same case (email becomes\ninvalid, then trigger alert)?\n\nThanks a lot for your help!\n"},{"id":"388609","messageId":"CAP8UFD231wb124-fKQcv-ddG96xncHanOnZA4jWEU3-shxTkGw@mail.gmail.com","threadId":"52492","inReplyTo":"CAHCo6soNwee3hN4i6v0KtxphKHa96v--e41KRqfHKV5i45OqcA@mail.gmail.com","subject":"Re: IaC monitoring with Git","fromName":"Christian Couder","fromEmail":"christian.couder@gmail.com","sentAt":"2019-12-20T09:29:49Z","receivedAt":"2019-12-20T09:30:05Z","isPatch":false,"sender":{"key":"christian.couder@gmail.com","avatar":"https://avatars.githubusercontent.com/u/208954?v=4"},"body":"Hi,\n\nOn Thu, Dec 19, 2019 at 10:31 PM Christopher Díaz Riveros\n<christopher.diaz.riv@gmail.com> wrote:\n\n> Would a valid approach for first issue be to set a pre-receive hook in\n> our repositories so that before the PR is merged, we check validity of\n> the contact email, a.k.a. owner tag (we assume validity means that\n> email exist), maybe via ldapsearch or another command like this?\n\nYou might find it easier and simpler to use CI tools like Travis CI,\nCircle CI, GitLab pipelines, GitHub Actions, and so on to run the\nchecks instead of using a hook.\n\n> For the second case, I'd assume git does not by default monitor\n> contents of files on a regular basis, does anybody have faced this\n> issue and successfully found a way to periodically check contents and\n> trigger alerts on repositories based on same case (email becomes\n> invalid, then trigger alert)?\n\nMany CI tools let you schedule jobs regularly.\n\nBest,\nChristian.\n"}]}