From ab2704a6f5a9ce2031cca03bc610b0e7c02553df Mon Sep 17 00:00:00 2001 From: AndrewLamb Date: Wed, 5 Apr 2023 14:45:11 +0100 Subject: [SO] Create Authorization Policies for SO - Create Authoriation Policies for SO - Add in initial authorized serviceaccounts for each sub component service Issue-ID: OOM-3128 Change-Id: Id18b7bb6cdb180b1173966e797032118b5b20621 Signed-off-by: AndrewLamb --- kubernetes/so/components/so-etsi-sol003-adapter/values.yaml | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'kubernetes/so/components/so-etsi-sol003-adapter/values.yaml') diff --git a/kubernetes/so/components/so-etsi-sol003-adapter/values.yaml b/kubernetes/so/components/so-etsi-sol003-adapter/values.yaml index 98edcebb29..35a42fac78 100755 --- a/kubernetes/so/components/so-etsi-sol003-adapter/values.yaml +++ b/kubernetes/so/components/so-etsi-sol003-adapter/values.yaml @@ -114,6 +114,15 @@ ingress: port: 9092 config: ssl: "redirect" +serviceMesh: + authorizationPolicy: + authorizedPrincipals: + - serviceAccount: robot-read + - serviceAccount: so-bpmn-infra-read + - serviceAccount: so-etsi-nfvo-ns-lcm-read + - serviceAccount: so-read + - serviceAccount: istio-ingress + namespace: istio-ingress nodeSelector: {} tolerations: [] affinity: {} -- cgit 1.2.3-korg