← Policy catalog
</> AuthorizationPolicy · Apache-2.0

Allow ServiceAccount

authorizationpolicy-workload-allow-serviceaccount

productIstio

Allow requests to the payments workload only from the specified service account principal.

What this is

A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.

Manifest

apiVersion: security.istio.io/v1
kind: AuthorizationPolicy
metadata:
  name: allow-serviceaccount
  namespace: default
  annotations:
    cenroq.io/displayName: "Allow ServiceAccount"
    cenroq.io/description: "Allow requests to the payments workload only from the specified service account principal."
spec:
  selector:
    matchLabels:
      app: payments
  action: ALLOW
  rules:
  - from:
    - source:
        principals:
        - cluster.local/ns/default/sa/payments-client

Save it as authorizationpolicy-workload-allow-serviceaccount.yaml — the commands below assume that name.

Apply it

This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:

$ kubectl apply -f ./authorizationpolicy-workload-allow-serviceaccount.yaml