[POLICY][COMMON] Create Authorization Policies for Policy
[oom.git] / kubernetes / policy / components / policy-clamp-ac-kserve-ppnt / values.yaml
index dddf025..3e6164a 100755 (executable)
@@ -21,7 +21,6 @@
 #################################################################
 global:
   persistence: {}
-  aafEnabled: false
   #Strimzi Kafka properties
   useStrimziKafka: set-via-parent-chart-global-value
   kafkaTopics:
@@ -38,20 +37,6 @@ secrets:
     login: '{{ .Values.restServer.user }}'
     password: '{{ .Values.restServer.password }}'
     passwordPolicy: required
-  - uid: keystore-password
-    type: password
-    externalSecret: '{{ tpl (default "" .Values.certStores.keyStorePasswordExternalSecret) . }}'
-    password: '{{ .Values.certStores.keyStorePassword }}'
-    passwordPolicy: required
-  - uid: truststore-password
-    type: password
-    externalSecret: '{{ tpl (default "" .Values.certStores.trustStorePasswordExternalSecret) . }}'
-    password: '{{ .Values.certStores.trustStorePassword }}'
-    passwordPolicy: required
-
-certStores:
-  keyStorePassword: Pol1cy_0nap
-  trustStorePassword: Pol1cy_0nap
 
 #################################################################
 # Application configuration defaults.
@@ -60,7 +45,6 @@ certStores:
 image: onap/policy-clamp-ac-kserve-ppnt:6.4.1
 pullPolicy: Always
 
-
 componentName: &componentName policy-clamp-ac-kserve-ppnt
 
 # application configuration
@@ -80,6 +64,11 @@ affinity: {}
 ingress:
   enabled: false
 
+serviceMesh:
+  authorizationPolicy:
+    authorizedPrincipals:
+      - serviceAccount: message-router-read
+
 # probe configuration parameters
 liveness:
   initialDelaySeconds: 20
@@ -100,8 +89,6 @@ service:
   ports:
     - name: kserve-api
       port: 8087
-      nodePort: 42
-
 
 flavor: small
 resources: