Files
ab-initio-manifests/rendered/manifests/k3s-dev/abinitio-platform/authgateway/v1_configmap_authgateway-external-config.yaml
2026-03-07 15:00:05 +00:00

1463 lines
64 KiB
YAML

apiVersion: v1
data:
ag.yaml: |
externalConfig:
authorizationGateway:
appserverType: tomcat
authentication:
type: local
authorization:
type: local
bridgeConnectionList:
- encryptionType: aes128-gcm
name: container-bridge
rpcSecret: file=/secrets/bridge/password
securityConfig: container-bridge-security
url: http://authgateway-importer:7070
db:
appserver:
password: file=/secrets/ag_appserver/password
username: ag_appserver
host: authgateway-rw.abinitio-db.svc
importer:
password: file=/secrets/ag_db_importer/password
username: ag_importer
mainSchema:
name: ag_main
metaSchema:
name: ag_meta
name: authgateway
port: "5432"
report:
password: file=/secrets/ag_report/password
username: ag_report
type: postgresql
logging:
directoryPath: /abinitio/webapp/logs
maxBackups: 5
packageForSupport:
encrypted: EncryptForNonAdmins
serverConfiguration:
cluster:
autoConfig:
hosts: authgateway-jgroup
port: 7800
protocol: TCP
enabled: true
encryption:
enabled: false
mtbridge:
defaultBridgeConnection: container-bridge
importHostServicesBridgeConnection: container-bridge
search:
index:
thread:
pool:
bootstrapSize: 1
size: 1
indexDirectoryRoot: file:///abinitio/data/searchIndex
urlFromBrowser: https://aidp.k3s.sg.ic.cloudguild.gcp.abinitio.com/authgateway
urlFromImporter: http://authgateway:8080/authgateway
websockets:
forceDisable: false
aic-credentials.xml: |
<?xml version='1.1' encoding='UTF-8'?>
<config>
</config>
default-resources.xml: |
<?xml version='1.1' encoding='UTF-8'?>
<config>
<initial>
<Entities>
<version>1.0</version>
<!--
Pre-register all product instances.
This allows the platform to create default groups, roles and users for the base platform.
-->
<AGProductInstance>
<AGProductInstance>AIC Gateway</AGProductInstance>
<Description>The gateway that brokers communication between AI Central components and large language models</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>AIC Gateway</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>AIC Web Application</AGProductInstance>
<Description>The web application that implements the Ab Initio AI assistant</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>AIC Web Application</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Authorization Gateway</AGProductInstance>
<Description>Authorization Gateway</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Authorization Gateway</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Cafe</AGProductInstance>
<Description>Cafe</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Cafe</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Control&gt;Center</AGProductInstance>
<Description>Control>Center</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Control&gt;Center</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<Description>Data Catalog Services</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Data Catalog Services</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>EMETR</AGProductInstance>
<Description>EME Technical Repository</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>EMETR</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Express&gt;It</AGProductInstance>
<Description>Express>It</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Express&gt;It</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Metadata Hub</AGProductInstance>
<Description>Metadata Hub</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>AIASP:mhub_meta@jdbc:postgresql://metadatahub-rw.abinitio-db.svc:5432/metadatahub</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Query&gt;It</AGProductInstance>
<Description>Query>It</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Query&gt;It</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Query&gt;It Administrator</AGProductInstance>
<Description>Query>It Administrator</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>Query&gt;It Administrator</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>TRW</AGProductInstance>
<Description>Technical Repository Web Interface</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>TRW</UUID>
</AGProductInstance>
<AGProductInstance>
<AGProductInstance>Runtime Locator (Bridge)</AGProductInstance>
<Description>Runtime Locator (Bridge)</Description>
<SupportsToken>Y</SupportsToken>
<URLAuthFragment />
<URLBase />
<UUID>runtime-locator-bridge</UUID>
</AGProductInstance>
<!--
Pre-create product instance roles. Products may have more roles than are specified but
the ones indicted are used within default AG Groups
-->
<AGProductRole>
<AGProductInstance>AIC Gateway</AGProductInstance>
<AGProductRole>AIC Gateway All Routes Role</AGProductRole>
<Description>Users with this role are allowed to use all routes configured in the AI Central Gateway</Description>
<IsDeleted>N</IsDeleted>
<Name>AIC Gateway All Routes Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>AIC Web Application</AGProductInstance>
<AGProductRole>ROLE_AI_CENTRAL_ADMIN</AGProductRole>
<Description>Permission to administer AI Central</Description>
<IsDeleted>N</IsDeleted>
<Name>AI Central Administrator</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>AIC Web Application</AGProductInstance>
<AGProductRole>ROLE_AI_CENTRAL_USER</AGProductRole>
<Description>Permission to log in to AI Central</Description>
<IsDeleted>N</IsDeleted>
<Name>AI Central User</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>ADMIN</AGProductRole>
<Description>Permission to administer</Description>
<IsDeleted>N</IsDeleted>
<Name>CAFE Administrator</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
<Description>Authenticated user role</Description>
<IsDeleted>N</IsDeleted>
<Name>CAFE Authenticated User</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>USER</AGProductRole>
<Description>User role</Description>
<IsDeleted>N</IsDeleted>
<Name>CAFE User</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Control&gt;Center</AGProductInstance>
<AGProductRole>ROLE_OP_ADMIN</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>Control>Center Administrator</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Control&gt;Center</AGProductInstance>
<AGProductRole>ROLE_OP_ANALYST</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>Control>Center Op Analyst</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_ADMIN</AGProductRole>
<Description>Permission to administer Data Catalog</Description>
<IsDeleted>N</IsDeleted>
<Name>Data Catalog Administrator</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_PHYS_DATASET_EDITOR</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>Data Catalog Phys Dataset Editor</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_USER</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>Data Catalog User</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99997</AGProductRole>
<Description>All permissions</Description>
<IsDeleted>N</IsDeleted>
<Name>eme-login</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99998</AGProductRole>
<Description>All permissions</Description>
<IsDeleted>N</IsDeleted>
<Name>eme-root</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Express&gt;It</AGProductInstance>
<AGProductRole>AB_APPCONF_ADMINISTRATOR</AGProductRole>
<Description>All permissions</Description>
<IsDeleted>N</IsDeleted>
<Name>AB_APPCONF_ADMINISTRATOR</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Express&gt;It</AGProductInstance>
<AGProductRole>AB_APPCONF_EDITOR</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>AB_APPCONF_EDITOR</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Express&gt;It</AGProductInstance>
<AGProductRole>AB_APPCONF_USER</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>AB_APPCONF_USER</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Administrator Role</AGProductRole>
<Description>Users belonging to the Administrator role have unrestricted access to
application functions, including administrative functions.</Description>
<IsDeleted>N</IsDeleted>
<Name>Administrator Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Approver Role</AGProductRole>
<Description>Users belonging to the Approver role can approve any submitted changes.</Description>
<IsDeleted>N</IsDeleted>
<Name>Approver Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Data Quality View Records with Issues Role</AGProductRole>
<Description>Users belonging to the Data Quality View Records with Issues Role can view
records within the dataset that contributed to data quality metrics.</Description>
<Name>Data Quality View Records with Issues Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>DiscoveryAdministratorRole</AGProductRole>
<Description>Administrative role that can access all of the Semantic Discovery views.</Description>
<IsDeleted>N</IsDeleted>
<Name>Discovery Administrator Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>DiscoveryOperatorRole</AGProductRole>
<Description>Operations role that can request Semantic Discovery job execution.</Description>
<IsDeleted>N</IsDeleted>
<Name>Discovery Operator Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Editor Role</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>Editor Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Entity API Save Options Role</AGProductRole>
<Description>Entity API Save Options Role</Description>
<IsDeleted>N</IsDeleted>
<Name>Entity API Save Options Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Importer Role</AGProductRole>
<Description>Users belonging to the Importer role may use the Metadata Importer.</Description>
<IsDeleted>N</IsDeleted>
<Name>Importer Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>MDP Administrator Role</AGProductRole>
<Description>Administrative role that can perform all Metadata Promotion activities.</Description>
<IsDeleted>N</IsDeleted>
<Name>MDP Administrator Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Product Interoperability Trust Role</AGProductRole>
<Description>Product Interoperability Trust Role</Description>
<IsDeleted>N</IsDeleted>
<Name>Product Interoperability Trust Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>User Role</AGProductRole>
<Description>Users belonging the User role may log in to the UI.</Description>
<IsDeleted>N</IsDeleted>
<Name>User Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Version Tag Configurer Role</AGProductRole>
<Description>Administrative role that can create, edit and delete Version Tag Related
Content Queries.</Description>
<IsDeleted>N</IsDeleted>
<Name>Version Tag Configurer Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Version Tag Editor Role</AGProductRole>
<Description>Administrative role that can create, edit and delete Version Tags.</Description>
<IsDeleted>N</IsDeleted>
<Name>Version Tag Editor Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Version Tag Promoter Role</AGProductRole>
<Description>Administrative role that can create, edit and delete promoted Version Tags.</Description>
<IsDeleted>N</IsDeleted>
<Name>Version Tag Promoter Role</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_administrator</AGProductRole>
<Description>Users with the qi_instance_administrator role can: . create roles/schemas (via
CREATEROLE privilege, and CREATE privilege on database absqldb) . change the AG
(Authorization
Gateway) connection configuration (ab_sql.ab_ag_config), . publish roles/resources to the
AG,
. view/kill active queries (absql.ab_query_impl), . create/modify dataspaces
(absql.ab_ds_data_space), . view the query log (ab_sql.ab_log), . do everything a
qi_instance_user can do Note that the CREATEROLE privilege will only be automatically
granted
to users with the qi_instance_administrator role if the Query>It instance is attached to
the
AG (Authorization Gateway). Otherwise, you have to explicitly alter a user to have the
CREATEROLE privilege.</Description>
<IsDeleted>N</IsDeleted>
<Name>qi_instance_administrator</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_superuser</AGProductRole>
<Description>Users with the qi_instance_superuser role can: . Anything that a user with the
qi_instance_administrator (or qi_instance_user) role can do, . Reconfigure data sources
owned
by other users, . Grant or revoke privileges on any table or schema, . Import catalogs
that
contain definitions for data sources that are owned by other users.</Description>
<IsDeleted>N</IsDeleted>
<Name>qi_instance_superuser</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_user</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>qi_instance_user</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Query&gt;It Administrator</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
<Description>Users with this role can log into the Query>It Administrator UI when it is
configured to use AG authentication</Description>
<IsDeleted>N</IsDeleted>
<Name>qi_administrator_ui_login</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>TRW</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
<Description>Users with this role can access the Technical Repository Web</Description>
<IsDeleted>N</IsDeleted>
<Name>User</Name>
</AGProductRole>
<AGProductRole>
<AGProductInstance>Runtime Locator (Bridge)</AGProductInstance>
<AGProductRole>GDE-User-Role</AGProductRole>
<Description></Description>
<IsDeleted>N</IsDeleted>
<Name>GDE-User-Role</Name>
</AGProductRole>
<!--
Pre-create AG users
- administrator
- DCS to MHUB interop user
- MHUB to DCS utility user
-->
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>aiadmin</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Administrator</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>Ab Initio Administrator</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/aiadmin/password</HashedPassword>
<Title/>
<Username>aiadmin</Username>
</AGPrincipal>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>dcs_utility</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Data Catalog Utility User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>Ab Initio Data Catalog Utility User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/dcs_utility_user/password</HashedPassword>
<Title/>
<Username>dcs_utility</Username>
</AGPrincipal>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>mhub_utility</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Metadata Hub Utility User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>Ab Initio Metadata Hub Utility User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/mhub_utility_user/password</HashedPassword>
<Title/>
<Username>mhub_utility</Username>
</AGPrincipal>
<!--
Pre-create AG groups
-->
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>AIC Gateway All Routes Group</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<ExternalGroupMapping></ExternalGroupMapping>
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>AIC Gateway All Routes Group</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>Ab Initio Editor Group</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>Ab Initio Joiner Group</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>Ab Initio Joiner Group</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>Ab Initio User Group</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>MetadataHub Utility Users</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>MetadataHub Utility Users</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>Data Catalog Utility Users</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>Data Catalog Utility Users</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>Product Interoperability Ticket Requester Group</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>Product Interoperability Ticket Requester Group</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>Ab Initio Administrator Group</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<AGPrincipal>
<SubType>AGGroup</SubType>
<AGPrincipal>GDE Users</AGPrincipal>
<ManagerSubType />
<Manager />
<PrincipalSubType />
<Principal />
<Description />
<EmailAddress />
<IsEnabled>Y</IsEnabled>
<MailStop />
<MobilePhone />
<Name>GDE Users</Name>
<OfficePhone />
<Password />
<Title />
<Username />
</AGPrincipal>
<!--
Pre-populate AG groups with AG users
-->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>mhub_utility</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>MetadataHub Utility Users</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>dcs_utility</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Data Catalog Utility Users</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>aiadmin</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Administrator Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>aiadmin</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Editor Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipalXref>
<ChildPrincipalSubType>AGGroup</ChildPrincipalSubType>
<ChildPrincipal>Ab Initio Administrator Group</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>AIC Gateway All Routes Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>aiadmin</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>GDE Users</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<!-- Add USER group and EDITOR group as subgroup to AIC group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGGroup</ChildPrincipalSubType>
<ChildPrincipal>Ab Initio Editor Group</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>AIC Gateway All Routes Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipalXref>
<ChildPrincipalSubType>AGGroup</ChildPrincipalSubType>
<ChildPrincipal>Ab Initio User Group</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>AIC Gateway All Routes Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<!-- Create each join user in joinUserList & assign to the Joiner Group -->
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>aic_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>aic_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/aic_join_user/password</HashedPassword>
<Title/>
<Username>aic_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>aic_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>cafe_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>cafe_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/cafe_join_user/password</HashedPassword>
<Title/>
<Username>cafe_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>cafe_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>cc_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>cc_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/cc_join_user/password</HashedPassword>
<Title/>
<Username>cc_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>cc_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>dcs_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>dcs_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/dcs_join_user/password</HashedPassword>
<Title/>
<Username>dcs_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>dcs_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>ei_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>ei_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/ei_join_user/password</HashedPassword>
<Title/>
<Username>ei_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>ei_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>eme_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>eme_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/eme_join_user/password</HashedPassword>
<Title/>
<Username>eme_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>eme_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>mhub_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>mhub_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/mhub_join_user/password</HashedPassword>
<Title/>
<Username>mhub_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>mhub_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>qi_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>qi_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/qi_join_user/password</HashedPassword>
<Title/>
<Username>qi_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>qi_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>qiadmin_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>qiadmin_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/qiadmin_join_user/password</HashedPassword>
<Title/>
<Username>qiadmin_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>qiadmin_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>runtime_locator_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>runtime_locator_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/runtime_locator_join_user/password</HashedPassword>
<Title/>
<Username>runtime_locator_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>runtime_locator_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>sd_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>sd_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/sd_join_user/password</HashedPassword>
<Title/>
<Username>sd_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>sd_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<AGPrincipal>
<SubType>AGUser</SubType>
<AGPrincipal>trw_join_user Join User</AGPrincipal>
<ManagerSubType/>
<Manager/>
<PrincipalSubType/>
<Principal/>
<Description>Ab Initio Application Join User</Description>
<EmailAddress/>
<ExternalGroupMapping/>
<IsEnabled>Y</IsEnabled>
<MailStop/>
<MobilePhone/>
<Name>trw_join_user Join User</Name>
<OfficePhone/>
<HashedPassword>file=/secrets/trw_join_user/password</HashedPassword>
<Title/>
<Username>trw_join_user</Username>
</AGPrincipal>
<!-- Add Join User to Joiner Group -->
<AGPrincipalXref>
<ChildPrincipalSubType>AGUser</ChildPrincipalSubType>
<ChildPrincipal>trw_join_user Join User</ChildPrincipal>
<ParentPrincipalSubType>AGGroup</ParentPrincipalSubType>
<ParentPrincipal>Ab Initio Joiner Group</ParentPrincipal>
<IsManagedByDirectoryService>N</IsManagedByDirectoryService>
</AGPrincipalXref>
<!-- Add Enhanced Auth Accepted IPs for Joiner Group -->
<AGEnhancedAuthPrincipal>
<AGEnhancedAuthenticationSubType>AGEnhancedAuthIPAccept</AGEnhancedAuthenticationSubType>
<AGEnhancedAuthentication>*.*.*.*</AGEnhancedAuthentication>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Joiner Group</AGPrincipal>
</AGEnhancedAuthPrincipal>
<AGEnhancedAuthPrincipal>
<AGEnhancedAuthenticationSubType>AGEnhancedAuthIPAccept</AGEnhancedAuthenticationSubType>
<AGEnhancedAuthentication>*:*:*:*:*:*:*:*</AGEnhancedAuthentication>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Joiner Group</AGPrincipal>
</AGEnhancedAuthPrincipal>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>AIC Gateway All Routes Group</AGPrincipal>
<AGProductInstance>AIC Gateway</AGProductInstance>
<AGProductRole>AIC Gateway All Routes Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>AIC Web Application</AGProductInstance>
<AGProductRole>ROLE_AI_CENTRAL_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>Control&gt;Center</AGProductInstance>
<AGProductRole>ROLE_OP_ANALYST</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_PHYS_DATASET_EDITOR</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99997</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99998</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>Express&gt;It</AGProductInstance>
<AGProductRole>AB_APPCONF_EDITOR</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Editor Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Editor Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Joiner Group</AGPrincipal>
<AGProductInstance>Authorization Gateway</AGProductInstance>
<AGProductRole>Product Interoperability Ticket Requester Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Joiner Group</AGPrincipal>
<AGProductInstance>Authorization Gateway</AGProductInstance>
<AGProductRole>Editor Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>AIC Web Application</AGProductInstance>
<AGProductRole>ROLE_AI_CENTRAL_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Control&gt;Center</AGProductInstance>
<AGProductRole>ROLE_OP_ANALYST</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99997</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Express&gt;It</AGProductInstance>
<AGProductRole>AB_APPCONF_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Query&gt;It Administrator</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>User Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>TRW</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio User Group</AGPrincipal>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_user</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>MetadataHub Utility Users</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Entity API Save Options Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>MetadataHub Utility Users</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Product Interoperability Trust Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>MetadataHub Utility Users</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Approver Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>MetadataHub Utility Users</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Importer Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Data Catalog Utility Users</AGPrincipal>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_ADMIN</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Data Catalog Utility Users</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>User Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Data Catalog Utility Users</AGPrincipal>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_superuser</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Data Catalog Utility Users</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99998</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Product Interoperability Ticket Requester Group</AGPrincipal>
<AGProductInstance>Authorization Gateway</AGProductInstance>
<AGProductRole>Product Interoperability Ticket Requester Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Product Interoperability Ticket Requester Group</AGPrincipal>
<AGProductInstance>Authorization Gateway</AGProductInstance>
<AGProductRole>Editor Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Authorization Gateway</AGProductInstance>
<AGProductRole>Administrator Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Cafe</AGProductInstance>
<AGProductRole>ADMIN</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Control&gt;Center</AGProductInstance>
<AGProductRole>ROLE_OP_ADMIN</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Data Catalog Services</AGProductInstance>
<AGProductRole>ROLE_DC_ADMIN</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99997</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99998</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Express&gt;It</AGProductInstance>
<AGProductRole>AB_APPCONF_ADMINISTRATOR</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Query&gt;It Administrator</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Administrator Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Approver Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Data Quality View Records with Issues Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>DiscoveryOperatorRole</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>DiscoveryAdministratorRole</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Entity API Save Options Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>MDP Administrator Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Version Tag Configurer Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Version Tag Editor Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Metadata Hub</AGProductInstance>
<AGProductRole>Version Tag Promoter Role</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>TRW</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_administrator</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>Query&gt;It</AGProductInstance>
<AGProductRole>qi_instance_superuser</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>AIC Web Application</AGProductInstance>
<AGProductRole>ROLE_AI_CENTRAL_ADMIN</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>Ab Initio Administrator Group</AGPrincipal>
<AGProductInstance>AIC Web Application</AGProductInstance>
<AGProductRole>ROLE_AI_CENTRAL_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>GDE Users</AGPrincipal>
<AGProductInstance>EMETR</AGProductInstance>
<AGProductRole>99997</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>GDE Users</AGPrincipal>
<AGProductInstance>TRW</AGProductInstance>
<AGProductRole>ROLE_AUTHENTICATED_USER</AGProductRole>
</AGPrincipalRole>
<AGPrincipalRole>
<AGPrincipalSubType>AGGroup</AGPrincipalSubType>
<AGPrincipal>GDE Users</AGPrincipal>
<AGProductInstance>Runtime Locator (Bridge)</AGProductInstance>
<AGProductRole>GDE-User-Role</AGProductRole>
</AGPrincipalRole>
</Entities>
</initial>
</config>
kind: ConfigMap
metadata:
labels:
abinitio/deployment: authgateway
app.kubernetes.io/instance: authgateway
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: authgateway
app.kubernetes.io/part-of: AbInitio
app.kubernetes.io/version: 4.4.1
helm.sh/chart: authgateway-2.4.3-a
name: authgateway-external-config
namespace: abinitio