Skip to content

Commit

Permalink
Merge pull request #1912 from bosch-io/improvement/helm-token-integra…
Browse files Browse the repository at this point in the history
…tion-subject

Helm gateway option for token-integration-subject
  • Loading branch information
alstanchev authored Mar 11, 2024
2 parents 41d088a + c49dc08 commit 2f5725f
Show file tree
Hide file tree
Showing 3 changed files with 5 additions and 1 deletion.
2 changes: 1 addition & 1 deletion deployment/helm/ditto/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ description: |
A digital twin is a virtual, cloud based, representation of his real world counterpart
(real world “Things”, e.g. devices like sensors, smart heating, connected cars, smart grids, EV charging stations etc).
type: application
version: 3.5.3 # chart version is effectively set by release-job
version: 3.5.4 # chart version is effectively set by release-job
appVersion: 3.5.3
keywords:
- iot-chart
Expand Down
2 changes: 2 additions & 0 deletions deployment/helm/ditto/templates/gateway-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -226,6 +226,8 @@ spec:
value: "{{ .Values.gateway.config.sse.throttling.limit }}"
- name: OAUTH_ALLOWED_CLOCK_SKEW
value: "{{ .Values.gateway.config.authentication.oauth.allowedClockSkew }}"
- name: OAUTH_TOKEN_INTEGRATION_SUBJECT
value: "{{ .Values.gateway.config.authentication.oauth.tokenIntegrationSubject }}"
{{- if .Values.gateway.extraEnv }}
{{- toYaml .Values.gateway.extraEnv | nindent 12 }}
{{- end }}
Expand Down
2 changes: 2 additions & 0 deletions deployment/helm/ditto/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1514,6 +1514,8 @@ gateway:
# authSubjects:
# - "{{ jwt:sub }}"
# - "{{ jwt:groups }}"
# configure the subject to inject in policy action activateTokenIntegration
tokenIntegrationSubject: "integration:{{policy-entry:label}}:{{jwt:aud}}"
# devops contains the configuration of the gateway's "/devops" API, e.g. access to it
devops:
# secured this controls whether "/devops" and "/api/2/connections" resources are secured or not
Expand Down

0 comments on commit 2f5725f

Please sign in to comment.