Altinn / Altinn/altinn-platform

DIS: Bootstrap new products

Open
#3,940 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
13
Forks
7
Avg merge
19h 21m
Merged PRs (30d)
76

Description

# Goal

Streamline enrollment of new products

# Why

When a new product want access to the cluster we need to streamline how the necessary resources for the product is created and permissions are granted to the right group in entra to those resources so that the team can get going in the matter of minutes

# Identified resources needed

From #3006

1. Identity used to push gitops oci artifacts to altinncr (how and where are these created and secrets distributed to the teams)
2. Namespace pr. product in dis-core
3. Syncroot with connected SA in namespace for each product (one pr. namespace)
4. Rbac rolebindings
5. ~~Baseline kyverno mutation policies (add network policies for health probes, add OTEL_EXPORTER_OTLP_ENDPOINT with otel collectors endpoint)~~
6. User access, read all (without secrets), in own namespace (restart, read secrets, ....) also pr product, Entra has product-groups
7. Grafan (kyverno mutate dashboards to ensure correct folder)
8. (Optional) Create specific Gateways to support custom FQDN

Point 5 is removed and replaced by a kro.run app-manifest (name needs to be decided). The mutating rule for adding this will be to complex, we should rather reap the added benefits of having a app manifest that simplifies the whole deployment process for the teams that just want a standard deployment in DIS

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or code entry points are named. Start by mapping how product namespaces, Syncroots, service accounts, RBAC rolebindings, OCI-push identities, Entra product groups, Grafana folders, and optional Gateways are currently created; also clarify the replacement kro.run app-manifest name and scope. Done should mean new-product enrollment creates the agreed resources and permissions consistently.

Written by the indexing model from the issue text.

Assessment

Tech stack
grafana, kubernetes
Domain
authorization, devops, infrastructure
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.