sudo: WARP sign-in, and comped accounts say Comped
Devices signed in to the Zero Trust org through the Cloudflare One agent reach sudo without the login page; g1t staff may enroll WARP. Done in the dashboard's API: org allow_authenticate_via_warp (8h), on the sudo app, and the g1t staff policy on the WARP enrollment app.
2 files+10−10/2 viewed
| 61 | 61 | list opens. Anyone else gets Access's own refusal; anyone Access lets in who | |
| 62 | 62 | is not in `STAFF_EMAILS` gets a 403 from the worker. | |
| 63 | 63 | ||
| 64 | + | ## Signing in through WARP | |
| 65 | + | ||
| 66 | + | Staff signed in to the Zero Trust org in the Cloudflare One agent (WARP) | |
| 67 | + | reach sudo without the login page: the org allows WARP sessions as Access | |
| 68 | + | sign-ins (8 hours), the sudo app accepts them, and the `g1t staff` policy | |
| 69 | + | is also on the WARP enrollment app, so staff can enroll their devices. | |
| 70 | + | The same two checks still apply: the Access policy, and `STAFF_EMAILS`. | |
| 71 | + | ||
| 64 | 72 | ## Working on it | |
| 65 | 73 | ||
| 66 | 74 | ```sh |
| 164 | 164 | new: { label: "New", tone: "plain" }, | |
| 165 | 165 | paid: { label: "Paid", tone: "info" }, | |
| 166 | 166 | reviewed: { label: "Reviewed", tone: "mint" }, | |
| 167 | − | internal: { label: "Internal", tone: "lavender" }, | |
| 167 | + | // Comped accounts: g1t covers their usage, with no ceiling. | |
| 168 | + | internal: { label: "Comped", tone: "lavender" }, | |
| 168 | 169 | }; | |
| 169 | 170 | ||
| 170 | 171 | export function TrustBadge({ trust }: { trust: Trust }) { |