cyberark / conjur-service-broker

Implementation of the Open Service Broker API for Conjur

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

An XDD document for increased PCF scalability is available

jvanderhoof opened this issue · comments

Challenge

Currently, hosts cannot be automatically provisioned into a corresponding organization/space layer. This means a policy joining a host to a layer (with permissions) must be generated and added to Conjur before a deployed application can retrieve credentials. Additionally, the application needs to be restarted after the permissions have been granted in Conjur, before the application can retrieve those credentials.

This means operators can't provision an application with the credentials the applications needs prior to the application being pushed.

Objective

Provide a workflow that allows operators to configure permissions prior to an application being pushed.

Desired Outcome

A detailed documented flow of how an operator will grant permissions to PCF applications. This document should start in Office 365 before moving to the epic.

XDD Link

https://cyberark365.sharepoint.com/:w:/s/Conjur/EdUWSJbziD1EpHHmeOBh2tcBhxqTH9bs-C-hUTaEyQIMYg?e=xj7HG3