Skip to content

Commit 95111c7

Browse files
committed
Update Audittrail with Nakadi write permissions
1 parent a7b4e78 commit 95111c7

File tree

2 files changed

+10
-1
lines changed

2 files changed

+10
-1
lines changed

cluster/config-defaults.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -667,6 +667,7 @@ audittrail_url: "https://audittrail.cloud.zalando.com"
667667
{{else}}
668668
audittrail_url: ""
669669
{{end}}
670+
audittrail_nakadi_url: ""
670671
audittrail_root_account_role: ""
671672

672673
audittrail_adapter_cpu: "50m"

cluster/manifests/audittrail-adapter/credentials.yaml

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{- if .Cluster.ConfigItems.audittrail_url }}
1+
{{- if or (ne .Cluster.ConfigItems.audittrail_url "") (ne .Cluster.ConfigItems.audittrail_nakadi_url "") }}
22
apiVersion: "zalando.org/v1"
33
kind: PlatformCredentialsSet
44
metadata:
@@ -8,7 +8,15 @@ metadata:
88
application: "audittrail-adapter"
99
spec:
1010
application: "audittrail-adapter"
11+
token_version: v2
1112
tokens:
13+
{{- end }}
14+
{{- if ne .Cluster.ConfigItems.audittrail_url "" }}
1215
audittrail:
1316
privileges: []
1417
{{- end }}
18+
{{- if ne .Cluster.ConfigItems.audittrail_nakadi_url "" }}
19+
nakadi:
20+
privileges:
21+
- com.zalando::nakadi.event_stream.write
22+
{{- end }}

0 commit comments

Comments
 (0)