-
Notifications
You must be signed in to change notification settings - Fork 20
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Keycloak 24.05. Release Candidate #66
Comments
@jjeroch had a look at the code the we need the following technical users: portal -> needs SSI Issuer Client + roles: issuer component -> needs Cl2-CX-Portal Client + roles: @evegufy /cc |
@Phil91 let us do some cleanups here request_credential |
…(consortia) (#620) * chore(service-accounts): remove sa-cl5-custodian-1 service account and rename sa-cl5-custodian-1 * chore(seeding-consortia): WIP onboard CX-Test-Access * chore: adjust seeding for cx test access Refs: eclipse-tractusx/portal-iam#66 --------- Co-authored-by: Phil Schneider <[email protected]>
remove: - BPDM Gate Read - BPDM Gate Read & Write - BPDM Partner Gate - BPDM Management - BPDM Pool add: - BPDM Sharing Admin - BPDM Sharing Input Manager - BPDM Sharing Input Consumer - BPDM Sharing Output Consumer - BPDM Pool Admin - BPDM Pool Consumer eclipse-tractusx/portal-iam#66
Summary
Update the keycloak image for release candidate 24.05.
Details
SD Factory Tech User
sa-cl5-custodian-1
to be removed - not needed anymore (note: already disabled the user in INT at the 24th of March to be able to test the scenario of not having this user anymore as part of the e2e tests) ✅ removedsa-cl5-custodian-2
- for discussion; actually interim (in release 24.05.) the connection will be stopped; afterwards it might get reconnected --> decision: stays inImpact to portal db seeding to be checked
New Client Issuer Component
Basic
Cl24-CX-SSI-CredentialIssuer
✅sa-cl2-04
needed (release image) which has permission to accessCl24-CX-SSI-CredentialIssuer
with all its roles ✅sa-cl24-01
needed (release image) which has permission to accessCl2-CX-Portal
with the roles ✅Add portal permissions ✅
Role Changes
decision_ssicredential
to the portal roleCX Admin
✅New DIM Client
Within release iam image:
sa-cl2-05
needed which has permission to accessCl2-CX-Portal
with the rolestore_didDocument
✅Not within release iam image / only consortia images (because hosted in some SAP IAM):
DIM-Middle-Layer
sa-dim-middle-layer-01
needed which has permission to accessDIM-Middle-Layer
with all its rolesNew technical users for the issuer function ✅ done under "New Client Issuer Component" section
Portal needs a configured technical user to connect portal with SSI-Credential-Issuer
Cl24-CX-SSI-CredentialIssuer
Issuer Component needs a configured technical user to connect back to the portal
Cl2-CX-Portal
Cl2-CX-Portal
permission)Cl2-CX-Portal
permission)Cl2-CX-Portal
permission)Cl2-CX-Portal
permission)Removal of portal permissions due to the new SSI Solution and Issuer component ✅
decision_ssicredential
permission from portalrequest_ssicredential
permission from portalRemoval of portal permissions due to clean-up/matching roles&rights matrix obsolete marked permissions ✅
upload_documents
permission from portalmy_user_account
permission from portalview_tech_roles
permission from portalsetup_client
permission from portalview_dataspaces
permission from portalfilter_apps
permission from portalview_services
permission from portalsubscribe_service_offering
permission from portalBPDM Roles & Right Concept adjustment ✅
Clean up
Cl7-CX-BPDM
Valid Origin: https://partners-pool.{env}.demo.catena-x.net/*
Description: BPDM Pool
Permissions:
Clean up
Cl16-CX-BPDMGate
Valid Origin: https://partners-gate.{env}.demo.catena-x.net/*
Description: Portal Gate
Permissions:
Inside the
technical_roles_management
removeInside the
technical_roles_management
newly createWith permissions:
sa-cl7-cx-1
✅sa-cl7-cx-2
- we need to inform Fabio - but I want to get rid of the user if possible ✅ (I asked Fabio, it's ok)sa-cl7-cx-3
- assignBPDM Pool Admin
✅sa-cl7-cx-4
- assignBPDM Pool Consumer
✅sa-cl7-cx-5
- assignBPDM Pool Admin
&BPDM Sharing Admin
✅sa-cl7-cx-6
- assignBPDM Pool Consumer
✅sa-cl7-cx-7
- assignBPDM Pool Admin
&BPDM Sharing Admin
✅The text was updated successfully, but these errors were encountered: