Uploaded image for project: 'Kogito'
  1. Kogito
  2. KOGITO-845

Create Kogito default Realm on Keycloak KogitoInfra

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Obsolete
    • Icon: Major Major
    • None
    • 0.6.0
    • Operator
    • None
    • 2020 Week 04-06 (from Jan 20), 2020 Week 07-09 (from Feb 10)

      After implementing KOGITO-85, we will also add the Kogito Realm being configured for use on internal components like Data Index.

      This realm should support JWT tokens and Quarkus Keycloak extension as provided by the keycloak profile on Data Index.

      The realm should be integrated with Openshift OAuth and any Service Account within the namespace has total access to the it. That means that any pods running within the namespace would query each other, as well as any user that has access to the namespace as well.

      The user kogito-service-viewer should be automatically added to this realm since it's the default Service Account for every pod that the Kogito Operator creates. So in the future, the services could use its own SA token (mounted in the pod) to query each other.

              rhn-support-zanini Ricardo Zanini
              rhn-support-zanini Ricardo Zanini
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: