Skip to content

OPA-01-001: Deployment guides and tutorials should refer to security docs #917

Closed
@tsandall

Description

The existing deployment guides for Kubernetes and Docker and the tutorials for different integrations do not deploy OPA a secured mode (e.g., no authorization policies are defined.) This is done to simplify the examples and make it easy for developers to inspect OPA in their test environment.

That being said, it would be good to include references in the deployment guides and tutorials on how users can secure OPA itself. At minimum we should point out that the example deployments are not secure.

Ref OPA-01-001

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions