Skip to content

Commit bce717a

Browse files
authored
fix: restrict codeengine control plane api (#639)
* fix: restrict codeengine control plane api * update CE APIs * update CE APIs
1 parent 5877777 commit bce717a

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

modules/fscloud/main.tf

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,12 @@ locals {
2727
"codeengine" : {
2828
"enforcement_mode" : "report"
2929
},
30+
"codeengine-service-control-plane" : {
31+
"enforcement_mode" : "report"
32+
},
33+
"codeengine-platform" : {
34+
"enforcement_mode" : "report"
35+
},
3036
"container-registry" : {
3137
"enforcement_mode" : "report"
3238
},
@@ -69,6 +75,9 @@ locals {
6975
"hs-crypto" : {
7076
"enforcement_mode" : "report"
7177
},
78+
"containers-kubernetes" : {
79+
"enforcement_mode" : "disabled"
80+
},
7281
"containers-kubernetes-management" : {
7382
"enforcement_mode" : "disabled"
7483
},
@@ -386,11 +395,16 @@ locals {
386395
messages-for-rabbitmq = local.icd_api_types,
387396
databases-for-mysql = local.icd_api_types
388397
mqcloud = local.icd_api_types
398+
codeengine = ["crn:v1:bluemix:public:context-based-restrictions::::api-type:control-plane", "crn:v1:bluemix:public:context-based-restrictions::::platform-api-type:"]
399+
codeengine-service-control-plane = ["crn:v1:bluemix:public:context-based-restrictions::::api-type:control-plane"]
400+
codeengine-platform = ["crn:v1:bluemix:public:context-based-restrictions::::platform-api-type:"]
389401
}
390402

391403
fake_service_names = {
392404
"containers-kubernetes-cluster" = "containers-kubernetes",
393405
"containers-kubernetes-management" = "containers-kubernetes"
406+
"codeengine-service-control-plane" = "codeengine"
407+
"codeengine-platform" = "codeengine"
394408
}
395409
}
396410

0 commit comments

Comments
 (0)