Altinn / Altinn/altinn-platform
DIS: Bootstrap new products
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 19h 21m
- Merged PRs (30d)
- 76
Description
# Goal
Streamline enrollment of new products
# Why
When a new product want access to the cluster we need to streamline how the necessary resources for the product is created and permissions are granted to the right group in entra to those resources so that the team can get going in the matter of minutes
# Identified resources needed
From #3006
1. Identity used to push gitops oci artifacts to altinncr (how and where are these created and secrets distributed to the teams)
2. Namespace pr. product in dis-core
3. Syncroot with connected SA in namespace for each product (one pr. namespace)
4. Rbac rolebindings
5. ~~Baseline kyverno mutation policies (add network policies for health probes, add OTEL_EXPORTER_OTLP_ENDPOINT with otel collectors endpoint)~~
6. User access, read all (without secrets), in own namespace (restart, read secrets, ....) also pr product, Entra has product-groups
7. Grafan (kyverno mutate dashboards to ensure correct folder)
8. (Optional) Create specific Gateways to support custom FQDN
Point 5 is removed and replaced by a kro.run app-manifest (name needs to be decided). The mutating rule for adding this will be to complex, we should rather reap the added benefits of having a app manifest that simplifies the whole deployment process for the teams that just want a standard deployment in DIS
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or code entry points are named. Start by mapping how product namespaces, Syncroots, service accounts, RBAC rolebindings, OCI-push identities, Entra product groups, Grafana folders, and optional Gateways are currently created; also clarify the replacement kro.run app-manifest name and scope. Done should mean new-product enrollment creates the agreed resources and permissions consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- grafana, kubernetes
- Domain
- authorization, devops, infrastructure
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100