Implement Istio Authorization Policies
Summary
See this MR for an example implementation and this comment for testing notes.
Designs
- Show closed items
Activity
-
Newest first Oldest first
-
Show all activity Show comments only Show history only
- Andrew Shoell added Big Bang Add-Ons anchore labels
added Big Bang Add-Ons anchore labels
- Andrew Shoell added to epic big-bang&159 (closed)
added to epic big-bang&159 (closed)
- Andrew Shoell added kindfeature priority5 teambigbang labels
added kindfeature priority5 teambigbang labels
- Andrew Shoell set weight to 1
set weight to 1
- Andrew Shoell changed the description
Compare with previous version changed the description
- Andrew Shoell changed iteration to Big Bang Iterations Oct 31, 2023 - Nov 13, 2023
changed iteration to Big Bang Iterations Oct 31, 2023 - Nov 13, 2023
- Ben Francis changed iteration to Big Bang Iterations Nov 14, 2023 - Nov 27, 2023
changed iteration to Big Bang Iterations Nov 14, 2023 - Nov 27, 2023
- Ben Francis changed iteration to Big Bang Iterations Nov 28, 2023 - Dec 11, 2023
changed iteration to Big Bang Iterations Nov 28, 2023 - Dec 11, 2023
- Ben Francis set weight to 2
set weight to 2
- GitLab Automation Bot removed iteration Big Bang Iterations Nov 28, 2023 - Dec 11, 2023
removed iteration Big Bang Iterations Nov 28, 2023 - Dec 11, 2023
- GitLab Automation Bot changed iteration to Big Bang Iterations Dec 12, 2023 - Dec 25, 2023
changed iteration to Big Bang Iterations Dec 12, 2023 - Dec 25, 2023
- Andrew Shoell set weight to 3
set weight to 3
- Ben Francis removed iteration Big Bang Iterations Dec 12, 2023 - Dec 25, 2023
removed iteration Big Bang Iterations Dec 12, 2023 - Dec 25, 2023
- Megan Wolf added teamSecurity & Compliance label and removed teambigbang label
added teamSecurity & Compliance label and removed teambigbang label
- Enoch Ofori assigned to @enochofori777
assigned to @enochofori777
- Andrew Shoell changed iteration to Big Bang Iterations Jan 23, 2024 - Feb 5, 2024
changed iteration to Big Bang Iterations Jan 23, 2024 - Feb 5, 2024
- GitLab Automation Bot changed iteration to Big Bang Iterations Feb 6, 2024 - Feb 19, 2024
changed iteration to Big Bang Iterations Feb 6, 2024 - Feb 19, 2024
- GitLab Automation Bot removed iteration Big Bang Iterations Jan 23, 2024 - Feb 5, 2024
removed iteration Big Bang Iterations Jan 23, 2024 - Feb 5, 2024
Removing iteration and assignee until this is picked up again.
- Jacob Ortiz removed iteration Big Bang Iterations Feb 6, 2024 - Feb 19, 2024
removed iteration Big Bang Iterations Feb 6, 2024 - Feb 19, 2024
- Jacob Ortiz unassigned @enochofori777
unassigned @enochofori777
- Enoch Ofori assigned to @enochofori777
assigned to @enochofori777
- Enoch Ofori added statusdoing label
added statusdoing label
- Enoch Ofori mentioned in merge request !207 (merged)
mentioned in merge request !207 (merged)
- Enoch Ofori removed statusdoing label
removed statusdoing label
- Enoch Ofori added statusreview label
added statusreview label
- Robert Massey mentioned in commit 1267aaeb
mentioned in commit 1267aaeb
- Robert Massey closed with merge request !207 (merged)
closed with merge request !207 (merged)
- Michael Martin mentioned in merge request big-bang/bigbang!3892 (merged)
mentioned in merge request big-bang/bigbang!3892 (merged)
- Michael Martin reopened
reopened
- Ryan Garcia added statusdoing label and removed statusreview label
added statusdoing label and removed statusreview label
- Owner
@chris.oconnell @ryan.j.garcia @massey.robert @enochofori777 Anchore fails to come up with hardening enabled
- create a cluster -- tested on local k3d / ec2 k3d / vanilla k8s cluster
- Enable anchore
- Enabled hardening per big-bang/bigbang!3892 (merged)
- install bigbang
anchore-feeds-xxx-xxx loops with error:
(Background on this error at: https://sqlalche.me/e/14/e3q8) [MainThread] 2024-03-26T17:01:14.758179 [MainThread] [anchore_enterprise_manager.util.db/connect_database()] [INFO] DB attempting to connect... [MainThread] 2024-03-26T17:01:14.764958 [MainThread] [anchore_enterprise_manager.util.db/connect_database()] [WARN] DB connection failed, retrying - exception: test connection failed - exception: (psycopg2.OperationalError) server closed the connection unexpectedly This probably means the server terminated abnormally before or while processing the request.
Removing the anchore AuthorizationPolicy kinds allows everything to start up
I'm not sure how the feeds work or what that
sqlalche.me
access site is. Might need a way to whitelist known,default feed sitesEdited by Michael Martin - Enoch Ofori changed iteration to Big Bang Iterations Apr 2, 2024 - Apr 15, 2024
changed iteration to Big Bang Iterations Apr 2, 2024 - Apr 15, 2024
- Enoch Ofori mentioned in merge request !227 (merged)
mentioned in merge request !227 (merged)
- Abimbola Abiola added statusready-to-work label and removed statusdoing label
added statusready-to-work label and removed statusdoing label
- Robert Massey changed milestone to %2.25.0
changed milestone to %2.25.0
- Jacob Ortiz added statusdoing label and removed statusready-to-work label
added statusdoing label and removed statusready-to-work label
- Robert Massey mentioned in commit 002e795a
mentioned in commit 002e795a
- Robert Massey closed with merge request !227 (merged)
closed with merge request !227 (merged)
- Ryan Garcia mentioned in merge request big-bang/bigbang!4141 (closed)
mentioned in merge request big-bang/bigbang!4141 (closed)
- Michael Martin mentioned in commit big-bang/bigbang@9ea29ce5
mentioned in commit big-bang/bigbang@9ea29ce5