apiVersion: v1
data:
ag.yaml: |
externalConfig:
authorizationGateway:
appserverType: tomcat
authentication:
type: local
authorization:
type: local
bridgeConnectionList:
- encryptionType: aes128-gcm
name: container-bridge
rpcSecret: file=/secrets/bridge/password
securityConfig: container-bridge-security
url: http://authgateway-importer:7070
db:
appserver:
password: file=/secrets/ag_appserver/password
username: ag_appserver
host: authgateway-rw.abinitio-db.svc
importer:
password: file=/secrets/ag_db_importer/password
username: ag_importer
mainSchema:
name: ag_main
metaSchema:
name: ag_meta
name: authgateway
port: "5432"
report:
password: file=/secrets/ag_report/password
username: ag_report
type: postgresql
logging:
directoryPath: /abinitio/webapp/logs
maxBackups: 5
packageForSupport:
encrypted: EncryptForNonAdmins
serverConfiguration:
cluster:
autoConfig:
hosts: authgateway-jgroup
port: 7800
protocol: TCP
enabled: true
encryption:
enabled: false
mtbridge:
defaultBridgeConnection: container-bridge
importHostServicesBridgeConnection: container-bridge
search:
index:
thread:
pool:
bootstrapSize: 1
size: 1
indexDirectoryRoot: file:///abinitio/data/searchIndex
urlFromBrowser: https://aidp.k3s.sg.ic.cloudguild.gcp.abinitio.com/authgateway
urlFromImporter: http://authgateway:8080/authgateway
websockets:
forceDisable: false
aic-credentials.xml: |
default-resources.xml: |
1.0
AIC Gateway
The gateway that brokers communication between AI Central components and large language models
Y
AIC Gateway
AIC Web Application
The web application that implements the Ab Initio AI assistant
Y
AIC Web Application
Authorization Gateway
Authorization Gateway
Y
Authorization Gateway
Cafe
Cafe
Y
Cafe
Control>Center
Control>Center
Y
Control>Center
Data Catalog Services
Data Catalog Services
Y
Data Catalog Services
EMETR
EME Technical Repository
Y
EMETR
Express>It
Express>It
Y
Express>It
Metadata Hub
Metadata Hub
Y
AIASP:mhub_meta@jdbc:postgresql://metadatahub-rw.abinitio-db.svc:5432/metadatahub
Query>It
Query>It
Y
Query>It
Query>It Administrator
Query>It Administrator
Y
Query>It Administrator
TRW
Technical Repository Web Interface
Y
TRW
Runtime Locator (Bridge)
Runtime Locator (Bridge)
Y
runtime-locator-bridge
AIC Gateway
AIC Gateway All Routes Role
Users with this role are allowed to use all routes configured in the AI Central Gateway
N
AIC Gateway All Routes Role
AIC Web Application
ROLE_AI_CENTRAL_ADMIN
Permission to administer AI Central
N
AI Central Administrator
AIC Web Application
ROLE_AI_CENTRAL_USER
Permission to log in to AI Central
N
AI Central User
Cafe
ADMIN
Permission to administer
N
CAFE Administrator
Cafe
ROLE_AUTHENTICATED_USER
Authenticated user role
N
CAFE Authenticated User
Cafe
USER
User role
N
CAFE User
Control>Center
ROLE_OP_ADMIN
N
Control>Center Administrator
Control>Center
ROLE_OP_ANALYST
N
Control>Center Op Analyst
Data Catalog Services
ROLE_DC_ADMIN
Permission to administer Data Catalog
N
Data Catalog Administrator
Data Catalog Services
ROLE_DC_PHYS_DATASET_EDITOR
N
Data Catalog Phys Dataset Editor
Data Catalog Services
ROLE_DC_USER
N
Data Catalog User
EMETR
99997
All permissions
N
eme-login
EMETR
99998
All permissions
N
eme-root
Express>It
AB_APPCONF_ADMINISTRATOR
All permissions
N
AB_APPCONF_ADMINISTRATOR
Express>It
AB_APPCONF_EDITOR
N
AB_APPCONF_EDITOR
Express>It
AB_APPCONF_USER
N
AB_APPCONF_USER
Metadata Hub
Administrator Role
Users belonging to the Administrator role have unrestricted access to
application functions, including administrative functions.
N
Administrator Role
Metadata Hub
Approver Role
Users belonging to the Approver role can approve any submitted changes.
N
Approver Role
Metadata Hub
Data Quality View Records with Issues Role
Users belonging to the Data Quality View Records with Issues Role can view
records within the dataset that contributed to data quality metrics.
Data Quality View Records with Issues Role
Metadata Hub
DiscoveryAdministratorRole
Administrative role that can access all of the Semantic Discovery views.
N
Discovery Administrator Role
Metadata Hub
DiscoveryOperatorRole
Operations role that can request Semantic Discovery job execution.
N
Discovery Operator Role
Metadata Hub
Editor Role
N
Editor Role
Metadata Hub
Entity API Save Options Role
Entity API Save Options Role
N
Entity API Save Options Role
Metadata Hub
Importer Role
Users belonging to the Importer role may use the Metadata Importer.
N
Importer Role
Metadata Hub
MDP Administrator Role
Administrative role that can perform all Metadata Promotion activities.
N
MDP Administrator Role
Metadata Hub
Product Interoperability Trust Role
Product Interoperability Trust Role
N
Product Interoperability Trust Role
Metadata Hub
User Role
Users belonging the User role may log in to the UI.
N
User Role
Metadata Hub
Version Tag Configurer Role
Administrative role that can create, edit and delete Version Tag Related
Content Queries.
N
Version Tag Configurer Role
Metadata Hub
Version Tag Editor Role
Administrative role that can create, edit and delete Version Tags.
N
Version Tag Editor Role
Metadata Hub
Version Tag Promoter Role
Administrative role that can create, edit and delete promoted Version Tags.
N
Version Tag Promoter Role
Query>It
qi_instance_administrator
Users with the qi_instance_administrator role can: . create roles/schemas (via
CREATEROLE privilege, and CREATE privilege on database absqldb) . change the AG
(Authorization
Gateway) connection configuration (ab_sql.ab_ag_config), . publish roles/resources to the
AG,
. view/kill active queries (absql.ab_query_impl), . create/modify dataspaces
(absql.ab_ds_data_space), . view the query log (ab_sql.ab_log), . do everything a
qi_instance_user can do Note that the CREATEROLE privilege will only be automatically
granted
to users with the qi_instance_administrator role if the Query>It instance is attached to
the
AG (Authorization Gateway). Otherwise, you have to explicitly alter a user to have the
CREATEROLE privilege.
N
qi_instance_administrator
Query>It
qi_instance_superuser
Users with the qi_instance_superuser role can: . Anything that a user with the
qi_instance_administrator (or qi_instance_user) role can do, . Reconfigure data sources
owned
by other users, . Grant or revoke privileges on any table or schema, . Import catalogs
that
contain definitions for data sources that are owned by other users.
N
qi_instance_superuser
Query>It
qi_instance_user
N
qi_instance_user
Query>It Administrator
ROLE_AUTHENTICATED_USER
Users with this role can log into the Query>It Administrator UI when it is
configured to use AG authentication
N
qi_administrator_ui_login
TRW
ROLE_AUTHENTICATED_USER
Users with this role can access the Technical Repository Web
N
User
Runtime Locator (Bridge)
GDE-User-Role
N
GDE-User-Role
AGUser
aiadmin
Ab Initio Application Administrator
Y
Ab Initio Administrator
file=/secrets/aiadmin/password
aiadmin
AGUser
dcs_utility
Ab Initio Data Catalog Utility User
Y
Ab Initio Data Catalog Utility User
file=/secrets/dcs_utility_user/password
dcs_utility
AGUser
mhub_utility
Ab Initio Metadata Hub Utility User
Y
Ab Initio Metadata Hub Utility User
file=/secrets/mhub_utility_user/password
mhub_utility
AGGroup
AIC Gateway All Routes Group
Y
AIC Gateway All Routes Group
AGGroup
Ab Initio Editor Group
Y
Ab Initio Editor Group
AGGroup
Ab Initio Joiner Group
Y
Ab Initio Joiner Group
AGGroup
Ab Initio User Group
Y
Ab Initio User Group
AGGroup
MetadataHub Utility Users
Y
MetadataHub Utility Users
AGGroup
Data Catalog Utility Users
Y
Data Catalog Utility Users
AGGroup
Product Interoperability Ticket Requester Group
Y
Product Interoperability Ticket Requester Group
AGGroup
Ab Initio Administrator Group
Y
Ab Initio Administrator Group
AGGroup
GDE Users
Y
GDE Users
AGUser
mhub_utility
AGGroup
MetadataHub Utility Users
N
AGUser
dcs_utility
AGGroup
Data Catalog Utility Users
N
AGUser
aiadmin
AGGroup
Ab Initio Administrator Group
N
AGUser
aiadmin
AGGroup
Ab Initio Editor Group
N
AGGroup
Ab Initio Administrator Group
AGGroup
AIC Gateway All Routes Group
N
AGUser
aiadmin
AGGroup
GDE Users
N
AGGroup
Ab Initio Editor Group
AGGroup
AIC Gateway All Routes Group
N
AGGroup
Ab Initio User Group
AGGroup
AIC Gateway All Routes Group
N
AGUser
aic_join_user Join User
Ab Initio Application Join User
Y
aic_join_user Join User
file=/secrets/aic_join_user/password
aic_join_user
AGUser
aic_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
cafe_join_user Join User
Ab Initio Application Join User
Y
cafe_join_user Join User
file=/secrets/cafe_join_user/password
cafe_join_user
AGUser
cafe_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
cc_join_user Join User
Ab Initio Application Join User
Y
cc_join_user Join User
file=/secrets/cc_join_user/password
cc_join_user
AGUser
cc_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
dcs_join_user Join User
Ab Initio Application Join User
Y
dcs_join_user Join User
file=/secrets/dcs_join_user/password
dcs_join_user
AGUser
dcs_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
ei_join_user Join User
Ab Initio Application Join User
Y
ei_join_user Join User
file=/secrets/ei_join_user/password
ei_join_user
AGUser
ei_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
eme_join_user Join User
Ab Initio Application Join User
Y
eme_join_user Join User
file=/secrets/eme_join_user/password
eme_join_user
AGUser
eme_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
mhub_join_user Join User
Ab Initio Application Join User
Y
mhub_join_user Join User
file=/secrets/mhub_join_user/password
mhub_join_user
AGUser
mhub_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
qi_join_user Join User
Ab Initio Application Join User
Y
qi_join_user Join User
file=/secrets/qi_join_user/password
qi_join_user
AGUser
qi_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
qiadmin_join_user Join User
Ab Initio Application Join User
Y
qiadmin_join_user Join User
file=/secrets/qiadmin_join_user/password
qiadmin_join_user
AGUser
qiadmin_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
runtime_locator_join_user Join User
Ab Initio Application Join User
Y
runtime_locator_join_user Join User
file=/secrets/runtime_locator_join_user/password
runtime_locator_join_user
AGUser
runtime_locator_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
sd_join_user Join User
Ab Initio Application Join User
Y
sd_join_user Join User
file=/secrets/sd_join_user/password
sd_join_user
AGUser
sd_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGUser
trw_join_user Join User
Ab Initio Application Join User
Y
trw_join_user Join User
file=/secrets/trw_join_user/password
trw_join_user
AGUser
trw_join_user Join User
AGGroup
Ab Initio Joiner Group
N
AGEnhancedAuthIPAccept
*.*.*.*
AGGroup
Ab Initio Joiner Group
AGEnhancedAuthIPAccept
*:*:*:*:*:*:*:*
AGGroup
Ab Initio Joiner Group
AGGroup
AIC Gateway All Routes Group
AIC Gateway
AIC Gateway All Routes Role
AGGroup
Ab Initio Editor Group
AIC Web Application
ROLE_AI_CENTRAL_USER
AGGroup
Ab Initio Editor Group
Cafe
USER
AGGroup
Ab Initio Editor Group
Cafe
ROLE_AUTHENTICATED_USER
AGGroup
Ab Initio Editor Group
Control>Center
ROLE_OP_ANALYST
AGGroup
Ab Initio Editor Group
Data Catalog Services
ROLE_DC_PHYS_DATASET_EDITOR
AGGroup
Ab Initio Editor Group
EMETR
99997
AGGroup
Ab Initio Editor Group
EMETR
99998
AGGroup
Ab Initio Editor Group
Express>It
AB_APPCONF_EDITOR
AGGroup
Ab Initio Editor Group
Metadata Hub
Editor Role
AGGroup
Ab Initio Joiner Group
Authorization Gateway
Product Interoperability Ticket Requester Role
AGGroup
Ab Initio Joiner Group
Authorization Gateway
Editor Role
AGGroup
Ab Initio User Group
AIC Web Application
ROLE_AI_CENTRAL_USER
AGGroup
Ab Initio User Group
Cafe
USER
AGGroup
Ab Initio User Group
Cafe
ROLE_AUTHENTICATED_USER
AGGroup
Ab Initio User Group
Control>Center
ROLE_OP_ANALYST
AGGroup
Ab Initio User Group
Data Catalog Services
ROLE_DC_USER
AGGroup
Ab Initio User Group
EMETR
99997
AGGroup
Ab Initio User Group
Express>It
AB_APPCONF_USER
AGGroup
Ab Initio User Group
Query>It Administrator
ROLE_AUTHENTICATED_USER
AGGroup
Ab Initio User Group
Metadata Hub
User Role
AGGroup
Ab Initio User Group
TRW
ROLE_AUTHENTICATED_USER
AGGroup
Ab Initio User Group
Query>It
qi_instance_user
AGGroup
MetadataHub Utility Users
Metadata Hub
Entity API Save Options Role
AGGroup
MetadataHub Utility Users
Metadata Hub
Product Interoperability Trust Role
AGGroup
MetadataHub Utility Users
Metadata Hub
Approver Role
AGGroup
MetadataHub Utility Users
Metadata Hub
Importer Role
AGGroup
Data Catalog Utility Users
Data Catalog Services
ROLE_DC_ADMIN
AGGroup
Data Catalog Utility Users
Metadata Hub
User Role
AGGroup
Data Catalog Utility Users
Query>It
qi_instance_superuser
AGGroup
Data Catalog Utility Users
EMETR
99998
AGGroup
Product Interoperability Ticket Requester Group
Authorization Gateway
Product Interoperability Ticket Requester Role
AGGroup
Product Interoperability Ticket Requester Group
Authorization Gateway
Editor Role
AGGroup
Ab Initio Administrator Group
Authorization Gateway
Administrator Role
AGGroup
Ab Initio Administrator Group
Cafe
ADMIN
AGGroup
Ab Initio Administrator Group
Control>Center
ROLE_OP_ADMIN
AGGroup
Ab Initio Administrator Group
Data Catalog Services
ROLE_DC_ADMIN
AGGroup
Ab Initio Administrator Group
EMETR
99997
AGGroup
Ab Initio Administrator Group
EMETR
99998
AGGroup
Ab Initio Administrator Group
Express>It
AB_APPCONF_ADMINISTRATOR
AGGroup
Ab Initio Administrator Group
Query>It Administrator
ROLE_AUTHENTICATED_USER
AGGroup
Ab Initio Administrator Group
Metadata Hub
Administrator Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
Approver Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
Data Quality View Records with Issues Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
DiscoveryOperatorRole
AGGroup
Ab Initio Administrator Group
Metadata Hub
DiscoveryAdministratorRole
AGGroup
Ab Initio Administrator Group
Metadata Hub
Entity API Save Options Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
MDP Administrator Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
Version Tag Configurer Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
Version Tag Editor Role
AGGroup
Ab Initio Administrator Group
Metadata Hub
Version Tag Promoter Role
AGGroup
Ab Initio Administrator Group
TRW
ROLE_AUTHENTICATED_USER
AGGroup
Ab Initio Administrator Group
Query>It
qi_instance_administrator
AGGroup
Ab Initio Administrator Group
Query>It
qi_instance_superuser
AGGroup
Ab Initio Administrator Group
AIC Web Application
ROLE_AI_CENTRAL_ADMIN
AGGroup
Ab Initio Administrator Group
AIC Web Application
ROLE_AI_CENTRAL_USER
AGGroup
GDE Users
EMETR
99997
AGGroup
GDE Users
TRW
ROLE_AUTHENTICATED_USER
AGGroup
GDE Users
Runtime Locator (Bridge)
GDE-User-Role
kind: ConfigMap
metadata:
labels:
abinitio/deployment: authgateway
app.kubernetes.io/instance: authgateway
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: authgateway
app.kubernetes.io/part-of: AbInitio
app.kubernetes.io/version: 4.4.1
helm.sh/chart: authgateway-2.4.3-a
name: authgateway-external-config
namespace: abinitio