The file says:
CloudFlare for URLs and DNS
Jupyter has a CloudFlare account that controls the DNS for all of the Jupyter domains. All Executive Council members have access to this account. For credentials see the Jupyter passwords service.
For security purposes and audit it is important that users do not access it by using the main password;
users should create their own account and be delegated. This way when someone does a change we know who,
and if their credentials are compromised we only need to audit their changes.
This also means we do not need to rotate the password when someone leave the EC for example, we can just revoke their delegation, or let the owner limit who has access to billing or destructive actions like kicking all other people out or changing the password...
This also let cloudflare detect suspicious activities better.
(This should be a general advice anyway for any service that allow delegation, I just happen to know Cloudflare is one of them)
The file says:
For security purposes and audit it is important that users do not access it by using the main password;
users should create their own account and be delegated. This way when someone does a change we know who,
and if their credentials are compromised we only need to audit their changes.
This also means we do not need to rotate the password when someone leave the EC for example, we can just revoke their delegation, or let the owner limit who has access to billing or destructive actions like kicking all other people out or changing the password...
This also let cloudflare detect suspicious activities better.
(This should be a general advice anyway for any service that allow delegation, I just happen to know Cloudflare is one of them)