diff --git a/devops/gcp/deploy/templates/authorization-policy.yml b/devops/gcp/deploy/templates/authorization-policy.yml index ba40c838c2f739b5780c2e8c630fe3094f3154d2..559a1e4083409737f2b74682c2f358702e8a031e 100644 --- a/devops/gcp/deploy/templates/authorization-policy.yml +++ b/devops/gcp/deploy/templates/authorization-policy.yml @@ -74,5 +74,9 @@ spec: - key: request.auth.claims[email] values: - "integration-tester@service.local" + - "storage@service.local" + - "datafier@service.local" + - "register@service.local" + - "notification@service.local" {{- end }} {{- end }} diff --git a/devops/gcp/deploy/templates/request-authentication.yml b/devops/gcp/deploy/templates/request-authentication.yml index 65cdee849450c2467d51c9d300079c49e6cab676..9c1b8cf065a56b6115fa916578e15162bb2564a8 100644 --- a/devops/gcp/deploy/templates/request-authentication.yml +++ b/devops/gcp/deploy/templates/request-authentication.yml @@ -9,13 +9,13 @@ spec: matchLabels: app: "{{ .Values.conf.appName }}" jwtRules: - - issuer: "https://keycloak.{{ .Values.conf.domain }}/auth/realms/{{ .Values.auth.realm }}" - jwksUri: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/auth/realms/{{ .Values.auth.realm }}/protocol/openid-connect/certs" + - issuer: "https://keycloak.{{ .Values.conf.domain }}/realms/{{ .Values.auth.realm }}" + jwksUri: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/realms/{{ .Values.auth.realm }}/protocol/openid-connect/certs" forwardOriginalToken: true - - issuer: "http://keycloak.{{ .Values.conf.domain }}/auth/realms/{{ .Values.auth.realm }}" - jwksUri: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/auth/realms/{{ .Values.auth.realm }}/protocol/openid-connect/certs" + - issuer: "http://keycloak.{{ .Values.conf.domain }}/realms/{{ .Values.auth.realm }}" + jwksUri: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/realms/{{ .Values.auth.realm }}/protocol/openid-connect/certs" forwardOriginalToken: true - - issuer: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/auth/realms/{{ .Values.auth.realm }}" - jwksUri: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/auth/realms/{{ .Values.auth.realm }}/protocol/openid-connect/certs" + - issuer: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/realms/{{ .Values.auth.realm }}" + jwksUri: "http://keycloak.{{ .Release.Namespace }}.svc.cluster.local/realms/{{ .Values.auth.realm }}/protocol/openid-connect/certs" forwardOriginalToken: true {{- end }}