Jesum Yip
11/01/2021, 1:30 AMJesum Yip
11/01/2021, 1:31 AMstorage:
driver: "blob"
blob:
bucket: "<gs://my-bucket-name>"
workDir: ${HOME}/tmp/cerbos/work
updatePollInterval: 10s
So how do I ensure my blob storage service is only accessible to Cerbos? I don't want prying eyes to see the policies in my blob storage service.Jesum Yip
11/01/2021, 1:33 AMstorage:
driver: "git"
git:
protocol: https
url: <https://github.com/cerbos/policy-test.git>
branch: main
subDir: policies
checkoutDir: ${HOME}/tmp/work/policies
updatePollInterval: 60s
operationTimeout: 30s
https:
username: cerbos
password: ${GITHUB_TOKEN}
Dennis (Cerbos)
Dennis (Cerbos)
GOOGLE_APPLICATION_CREDENTIALS
environment variable to specify service account keyJesum Yip
11/01/2021, 1:44 AMJesum Yip
11/01/2021, 1:46 AMDennis (Cerbos)
Jesum Yip
11/01/2021, 1:50 AMDennis (Cerbos)
Dennis (Cerbos)
// The following query parameters are supported:
//
// - access_id: sets Options.GoogleAccessID
// - private_key_path: path to read for Options.PrivateKey
//
// Currently their use is limited to SignedURL.
Dennis (Cerbos)
Jesum Yip
11/01/2021, 2:37 AMJesum Yip
11/01/2021, 2:37 AM