Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update dashboard documents to include threat model related action items #1250

Open
nithyatsu opened this issue Sep 25, 2024 · 0 comments
Open
Labels

Comments

@nithyatsu
Copy link
Contributor

nithyatsu commented Sep 25, 2024

Currently, we can access the application on http but since we only access the application on localhost using Kubernetes port-forward. We should provide Radius documentation that captures below guidelines to be followed if/when a customer chooses to allow Dashboard access to multiple users and/ or make dashboard public facing.

  1. Dashboard should be accessed only on HTTPS if it should be available outside cluster.

  2. Enable authentication on Dashboard. This could be tied to RBAC support on Radius, since we might want the same users to be allowed dashboard logins by default with permissions configured using Backstage permission system.

  3. The Backstage permissions system should be enabled and configured to restrict access as necessary.

AB#13254

@nithyatsu nithyatsu changed the title nithyatsu update dashboard documents to include threat model related action items Sep 25, 2024
@willtsai willtsai transferred this issue from radius-project/dashboard Sep 26, 2024
@willtsai willtsai added triaged and removed triaged labels Sep 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants