cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IAM Policies - Restric metrics, entities for namespace scope

Patryksp
Observer

Hi,

Currently we are working on creating IAM policies in order to restrict Grail data for only one namespace. With logs and events there is no problem (ALLOW storage:events:read, storage:logs:read where storage:k8s.namespace.name = "namespace-name";)

When it comes to the metrics or entities, even creating the security_context does not have the intended effect.
There is a possibilty that it doesn't work because we dont have metrics in Grail enabled.

Does anybody faced the same "issue"?

Best Regards
Patryk

1 REPLY 1

jaume_reverte
Dynatrace Advisor
Dynatrace Advisor

Hello Patryksp, 

Yes, for access management to the information stored in Grail to work, you need to have the information stored in Grail. 

Hope you a good monitoring!
Jaume Reverte

Featured Posts