As my own company is growing, we fully trust all employees, (limiting only what is essential), but, a dev ops guy if he was so inclined could technically do something like this... It always scares me.
As my own company is growing, we fully trust all employees, (limiting only what is essential), but, a dev ops guy if he was so inclined could technically do something like this... It always scares me.
For really important accounts - we have three people who each know two thirds of the password. It requires two people to then log in and do damage.
For example if the root password was CatDogFish then
Person1: CatDog_
Person2: _DogFish
Person3: Cat_Fish
Two people can then log in and watch what the other person is doing.
Because if not, once you are admin, you can install programs that let you become admin again at will.
Password rotation becomes necessary, and a little bit riskier, because now you have to deal with accidental lock-outs in a sane, coordinated manner.
You are stuck trusting somebody, no matter what. Its turtles all the way down.
Soon, dear throwaway, you'll be telling me we should live in fear of the locksmiths, for all their key blanks and such fiendish metal files to abrade them with. What if they should file down a butter knife into the shape of my precious bicycle chain's key?
But it's not a bad system.
Beyond that, be sure to keep regular backups (and test them), and audit all user actions. (feed the logs into something like Splunk, running on a separate machine)
And do backups. And then backups of those backups.
That's probably because when my grandmother died, my boss at QueBIT said "Ok, go home, call me when you can work again - however long that takes." There was never a discussion of PTO/HR policy, just human treatment.
Also remember to test restoring your backups or they don't count.
I worked retail to pay for college. Could always tell when a manager was getting the boot; they'd order new cylinders for all the doors. You kind of have to have that plan in place in IT too.
That's how I do it, anyway.
We can grant that this can be logistically difficult at certain scales, but it doesn't fall into the "engineering-impossible" bucket until you reach Facebook's size.
I don't know of any server provider (bare metal or cloud) that forces users to allow the company full access to their data (outside of managed providers were you voluntarily give this up , as you're paying them to fully manage your server)
If the CI/CD is done right, then no DevOps staff has any access to any servers and no one can delete anything except a scripts and AWS configurations.
The whole problem with limiting permissions is that you have to do all the work of deleting files, servers and drives.
covfefe
So THAT'S what it means!