Skip to content

Add support for HTTPS conn with mTLS and read-only permissions (OpenFGA) #14

Description

@bmarinov

A production setup would involve running the collector with minimal (read-only) permissions.

The Incus cert authorization only supports project-scoped permissions - https://linuxcontainers.org/incus/docs/main/authorization/#tls-authorization and is not enough here..

Tasks:

  • Set up OpenFGA test env
  • Use HTTPS API with client certificates for authentication
  • Document FGA permissions needed for the collector (get all instances, get instance, get events)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions