{ Community }
  • Academy
  • Docs
  • Developers
  • Resources
    • Community Articles
    • Apigee on GitHub
    • Code Samples
    • Videos & eBooks
    • Accelerator Methodology
  • Support
  • Ask a Question
  • Spaces
    • Product Announcements
    • General
    • Edge/API Management
    • Developer Portal (Drupal-based)
    • Developer Portal (Integrated)
    • API Design
    • APIM on Istio
    • Extensions
    • Business of APIs
    • Academy/Certification
    • Adapter for Envoy
    • Analytics
    • Events
    • Hybrid
    • Integration (AWS, PCF, Etc.)
    • Microgateway
    • Monetization
    • Private Cloud Deployment
    • 日本語コミュニティ
    • Insights
    • IoT Apigee Link
    • BaaS/Usergrid
    • BaaS Transition/Migration
    • Apigee-127
    • New Customers
    • Topics
    • Questions
    • Articles
    • Ideas
    • Leaderboard
    • Badges
  • Log in
  • Sign up

Get answers, ideas, and support from the Apigee Community

  • Home /
  • Microgateway /
avatar image
0
Question by Benjamin Goldman · Feb 05, 2016 at 02:08 AM · 365 Views Private Cloudsecuritysetup

Do you guys have any guidance on how to set up an RBAC role to support micro gateway w/o having to use an org admin accout

HI folks!

I am wondering if Apigee has any guidance on how to avoid using Org Admin accounts to connect micro gateway to edge/private-cloud.

I dont want to distribute account information w/ that much power to my micro servers....

Comment
Add comment
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

Close

2 Answers

  • Sort: 
avatar image
0
Best Answer

Answer by prabhat · Feb 05, 2016 at 09:21 PM

So as part of configuration aka wiring of edgemicro with an org, it deploys edgemicro-auth proxy which needs org admin credentials. But I hear what you are saying. Assuming edgemicro-auth is already deployed by org admins, one should be able to do the rest without requiring orgadmin credentials.

In mean time, I think what couple of other folks have done is use orgadmin credentials which updates agent's config.yaml, the updated config gets pushed to code repo which other folks then use.

Comment
Add comment Show 1 · Link
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users
avatar image Benjamin Goldman · Feb 05, 2016 at 09:28 PM 0
Link

can you move this to an answer? i think this will do it - we just have to model it.

avatar image
0

Answer by prabhat · Feb 05, 2016 at 03:40 AM

Hi Benjamin,

Org admin credentials are only needed during initial setup. During run time, whoever needs to operate Microgateway only needs key and secret that gets generated during that initial setup by org admins.

Comment
Add comment Show 2 · Link
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users
avatar image Benjamin Goldman · Feb 05, 2016 at 06:05 PM 0
Link

So that means that i need to have a uid/pw of an org admin account deployed in a package, golden image, etc for automated deployments.

I understand that this is a "one time" use - but I am very much against distributing (even encrypted) uid/pw's in deployment packages. In fact i suspect i have a corporate security policy strictly forbidding it :)

on the other hand - I dont have one that prevents me from doing the same thing w/ some sort of limited permission set account.... which is why im asking this specific question.

avatar image prabhat ♦ Benjamin Goldman · Feb 05, 2016 at 09:21 PM 1
Link

So as part of configuration aka wiring of edgemicro with an org, it deploys edgemicro-auth proxy which needs org admin credentials. But I hear what you are saying. Assuming edgemicro-auth is already deployed by org admins, one should be able to do the rest without requiring orgadmin credentials.

In mean time, I think what couple of other folks have done is use orgadmin credentials which updates agent's config.yaml, the updated config gets pushed to code repo which other folks then use.

Follow this Question

Answers Answers and Comments

32 People are following this question.

avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image

Related Questions

How long does Edgemicro cache API Key information? 1 Answer

deploying edgemicro-auth app giving - Error: Error uploading policy: 400 2 Answers

Few Questions on Microgateway OAuth implementation 2 Answers

edgemicro on cloud - unable to complete setup 2 Answers

spikearrest: how to report the number of rejected calls? 2 Answers

  • Products
    • Edge - APIs
    • Insights - Big Data
    • Plans
  • Developers
    • Overview
    • Documentation
  • Resources
    • Overview
    • Blog
    • Apigee Institute
    • Academy
    • Documentation
  • Company
    • Overview
    • Press
    • Customers
    • Partners
    • Team
    • Events
    • Careers
    • Contact Us
  • Support
    • Support Overview
    • Documentation
    • Status
    • Edge Support Portal
    • Privacy Policy
    • Terms & Conditions
© 2021 Apigee Corp. All rights reserved. - Apigee Community Terms of Use - Powered by AnswerHub
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Create an article
  • Post an idea
  • Spaces
  • Product Announcements
  • General
  • Edge/API Management
  • Developer Portal (Drupal-based)
  • Developer Portal (Integrated)
  • API Design
  • APIM on Istio
  • Extensions
  • Business of APIs
  • Academy/Certification
  • Adapter for Envoy
  • Analytics
  • Events
  • Hybrid
  • Integration (AWS, PCF, Etc.)
  • Microgateway
  • Monetization
  • Private Cloud Deployment
  • 日本語コミュニティ
  • Insights
  • IoT Apigee Link
  • BaaS/Usergrid
  • BaaS Transition/Migration
  • Apigee-127
  • New Customers
  • Explore
  • Topics
  • Questions
  • Articles
  • Ideas
  • Badges