Commit 60c6e2f5 authored by Adil Farrukh's avatar Adil Farrukh
Browse files

Add tier 2 coverage details

parent 8298aff8
Loading
Loading
Loading
Loading
+20 −0
Original line number Diff line number Diff line
@@ -150,6 +150,26 @@ Please do not escalate for general Rails concerns.

---

### Authn/Authz/Pipeline Security

**Expertise Areas:**

- Authentication (SAML, LDAP, OAuth login, Access tokens such as PATs/PrAT/GrATs/CI_JOB_TOKENS)
- Authentication (Enterprise users, Service accounts and Cloud Connector authentication)
- Authorization (Custom roles, Granular permissions on CI_JOB_TOKENS/PATs, ProjectAuthorizationWorker)
- Pipeline Security (OIDC with ID tokens, Secrets manager, External Secrets integrations, Build attestations and Cosign integration)

**When to Escalate:**

- Incidents impacting login or authentication to GitLab.com
- Incidents causing severe distruption due to sidekiq overload on permission update workers
- SIRT issues S2 and above that reuqire immediate action from the engineering team to remediate the problem.
- Recent feature additions for secrets manager, granular permissions or authentication services that are degrading availability of GitLab.com

**Coverage:** 24x5 (Monday-Friday, business hours but best effort for APAC)

---

## Coverage Expectations

- **24x5 Coverage**: Monday 00:00 UTC through Friday 23:59 UTC