{"repo":"otterize/intents-operator","free":true,"listed":false,"github":"https://github.com/otterize/intents-operator","clone":"git clone https://github.com/otterize/intents-operator.git","description":"Manage network policies, AWS, GCP & Azure IAM policies, Istio Authorization Policies, and Kafka ACLs in a Kubernetes cluster with ease.","language":"Go","stars":313,"topics":["acl","ibac","intents","kafka","kubernetes","mtls","networkpolicies","operator","controller","go"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Otterize intents operator About Quickstart & Docs How does the intents operator work? Network policies AWS IAM policies Azure IAM policies Google Cloud IAM policies Kafka mTLS & ACLs Deducing workload identities Bootstrapping Read more Development Contributing Slack About The Otterize intents operator is a tool used to easily automate the creation of network policies and Kafka ACLs in a Kubernetes cluster using a human-readable format, via a custom resource. Users declare each client's intents to access specific servers (represented as the kind ClientIntents ); the operator automatically labels the relevant pods accordingly, and creates the corresponding network policies and Kafka ACLs. Here is an example of a ClientIntents resource enabling traffic from my-client to web-server and kafka-server : How does the intents operator work? Network policies The intents operator automatically creates, updates and deletes network policies, and automatically labels client and server pods, to match declarations in client intents files. The policies created are Ingress -based, so source pods are labeled with a can-access- =true while destination pods are labeled with has-identity= . The example above results in the following network policy being created: For more usage example see the network policy tutorial. AWS IAM The intents operator, together with the credentials operator, enables the intent-based declarative management of AWS IAM roles and policies. To enable AWS access for a pod, fo","default_branch":null,"files":null,"tree":[],"storefront":"/r/otterize","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/otterize/intents-operator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}