Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-3047

Service Mesh Security Guide improvements - Securing the Control Plane

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Obsolete
    • Icon: Major Major
    • None
    • OSSM 2.1.0
    • Documentation

      Service Mesh users frequently have questions about how to secure their applications when using Service Mesh. This is a topic that cross multiple areas of OpenShift, Kubernetes and Service Mesh.

      This guide should start once the mesh is created, and should cover:

       

      Customer Questions that relate:

      • How do you secure the control plane? How do you control who is allowed to add projects to a given member roll?
      • How do you enforce "zero trust networking"? (admittedly, this has multiple meanings, but we can give guidance)
      • How do you restrict namespaces from communicating?
      • How do you restrict services from communicating?

       

      This internal document provides a potential outline - though it needs to be updated and reviewed:

      https://docs.google.com/document/d/1YsyoZn9gxRP8P3Vwm5-SGxQ1XV9JuGApzgDADiK86KQ/edit?usp=sharing

       

      QE POC: yuaxu@redhat.com 

       

            Unassigned Unassigned
            jlongmui@redhat.com Jamie Longmuir
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: