Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-3047

Service Mesh Security Guide improvements - Securing the Control Plane

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Obsolete
    • Icon: Major Major
    • None
    • OSSM 2.1.0
    • Documentation

      Service Mesh users frequently have questions about how to secure their applications when using Service Mesh. This is a topic that cross multiple areas of OpenShift, Kubernetes and Service Mesh.

      This guide should start once the mesh is created, and should cover:

       

      Customer Questions that relate:

      • How do you secure the control plane? How do you control who is allowed to add projects to a given member roll?
      • How do you enforce "zero trust networking"? (admittedly, this has multiple meanings, but we can give guidance)
      • How do you restrict namespaces from communicating?
      • How do you restrict services from communicating?

       

      This internal document provides a potential outline - though it needs to be updated and reviewed:

      https://docs.google.com/document/d/1YsyoZn9gxRP8P3Vwm5-SGxQ1XV9JuGApzgDADiK86KQ/edit?usp=sharing

       

      QE POC: yuaxu@redhat.com 

       

              Unassigned Unassigned
              jlongmui@redhat.com Jamie Longmuir
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: