-
Notifications
You must be signed in to change notification settings - Fork 63
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
support restricted option, jolokia agent, rbac, read only root, minimal #1037
Conversation
this pr includes support for:
|
9f8fb65
to
da54c23
Compare
I have remove the use of JDK_JAVA_ARGS in restricted mode, possibly, to avoid command line limitations, we may have to push these into a cmd file in the future, but that could also be a secret, as an easy way to supply different values. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great work!!! It provides a predictable and secure deployment.
496b8d2
to
f519654
Compare
If I understand the code correctly the mtls jolokia client will only be available in restricted mode. But I think if |
yes. I think it will be easier to fix #1036 with these changes. But #1036 is not resolved by this change and thinking some more, maybe the presence of an operator cert and operator trust bundle is sufficient to initiate mtls, if they are present, make use of them. |
…ead only root, minimal
No description provided.