Skip to content

docs(adr): Add BU-user ArgoCD UI access model to ADR-002 - #8553

Merged
William Ngufor (nguforw-moj) merged 1 commit into
mainfrom
docs/adr-002-argocd-bu-access
Sep 24, 2026
Merged

William Ngufor (nguforw-moj) merged 1 commit into
mainfrom
docs/adr-002-argocd-bu-access

Conversation

@nguforw-moj

Copy link
Copy Markdown
Contributor

ADR-002 specified deployment-side tenant isolation but never defined how BU engineers reach the ArgoCD UI (the gap behind #8548).

Documents the two-layer access model (Identity Center global VIEWER for UI entry, per-BU AppProject roles for Application visibility), the BU-to-identity-group mapping keyed on the GitHub business-units parent groups, and the group-tier asymmetry vs the product.yaml AWS/EKS path.

Records the four onboarded BU group mappings (with a reviewer-confirm callout on octo/cd, inferred from child-team naming) and the anticipated future BU groups, plus the operational dependency that squad teams must be nested under their BU parent to inherit UI access.

Implemented in ministryofjustice/modernisation-platform-environments#19301.

Part of #8548

ADR-002 specified deployment-side tenant isolation but never defined how
BU engineers reach the ArgoCD UI. Document the two-layer access model
(Identity Center global VIEWER for UI entry, per-BU AppProject roles for
Application visibility), the BU-to-identity-group mapping keyed on the
GitHub business-units parent groups, and the group-tier asymmetry versus
the product.yaml AWS/EKS access path.

Records the four onboarded BU group mappings (with a reviewer-confirm
callout on octo and cd, which are inferred from child-team naming) and
the anticipated future BU groups, plus the operational dependency that
squad teams must be nested under their BU parent to inherit UI access.

Part of #8548

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified that BU parent GH teams are a strategic decision and can be used going forward.

@nguforw-moj
William Ngufor (nguforw-moj) merged commit 519a469 into main Sep 24, 2026
3 checks passed
@nguforw-moj
William Ngufor (nguforw-moj) deleted the docs/adr-002-argocd-bu-access branch September 24, 2026 10:14
@github-project-automation github-project-automation Bot moved this to 🥇 Done in Cloud Platform Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: 🥇 Done

Development

Successfully merging this pull request may close these issues.

2 participants