# Venska ## Goal To be done Transferring the client to sub-accounts, in order to * cost allocation * coast tracking * separation of customer systems from internal systems * ease of handing over infrastructure * preventing one system's vulnerabilities from being used to take control of the rest of the infrastructure ## Ealier The client instances were in a Jit-owned space called JIT-OLD. It was connected directly to the network where internal instances were served. Access to the machine was available from our VPN via ssh. And the output of services to the world was handled by an instance called AWSProxy. Our gitlab was also used. ## Currently Currently, a new account has been created, separate from JIT services. Currently, the only connection we have between Venska and us is managing the IAM to define account access and passing the venska2.jit.team subdomain over route 53. They currently use 2 instances of Jenskins and gitlab. Both websites will be released into the world using Load Balancers. Internal resources cannot be accessed from within the Venska network. ## Diagram