You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
However, SAP Services and especially Istio seem to require some capabilities or extended rights.
These should be listed in technical documentation. Above all, a fundamental hardening of the installations - especially in this environment - is not an option but a necessary measure.
Edge Integration Cell on SUSE:
https://documentation.suse.com/sbp/sap-other/html/SAP-EIC/index.html#
Your document does not mention any settings regarding RKE2 Security. Only a screenshot shows a ‘default’ policy.
We usually harden our RKE2 clusters completely according to CIS and others - this includes the following spec of the
kind: Cluster
However, SAP Services and especially Istio seem to require some capabilities or extended rights.
These should be listed in technical documentation. Above all, a fundamental hardening of the installations - especially in this environment - is not an option but a necessary measure.
Another question is whether it would not make more sense to use existing operators for PostgreSQL and Redis - especially as these would make this point ( https://documentation.suse.com/sbp/sap-other/html/SAP-EIC/index.html#selfSignedCertificates ) elegantly obsolete.
Best regards
Sebastian
The text was updated successfully, but these errors were encountered: