feat(auth-jwt), fix|docs(charts): Security Assessment #27
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
WHAT
Provides a useful default authentication configuration (based on api-key hashes) which can be easily adopted, e.g. to use jwt-based authentication.
WHY
Security Assessment Threat Mitigation
FURTHER NOTES
Currently, we need to copy the EDC charts, because the helm value/template structure is significantly changed by introducing multiple dataplanes (of which the agent plane is one option). A reference to the original chart has been added right into the documentation.
The chartlint workflow already looks like the final upgrade workflow, but since the EDC charts are always depending on some external service (hashicorp, azure-vault), we cannot easily deploy (and hence upgrade-test) the charts.
Closes #24
Explains but not closes #26