authorizationpolicy-workload-allow-serviceaccount
Allow requests to the payments workload only from the specified service account principal.
A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.
apiVersion: security.istio.io/v1
kind: AuthorizationPolicy
metadata:
name: allow-serviceaccount
namespace: default
annotations:
cenroq.io/displayName: "Allow ServiceAccount"
cenroq.io/description: "Allow requests to the payments workload only from the specified service account principal."
spec:
selector:
matchLabels:
app: payments
action: ALLOW
rules:
- from:
- source:
principals:
- cluster.local/ns/default/sa/payments-clientSave it as authorizationpolicy-workload-allow-serviceaccount.yaml — the commands below assume that name.
This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:
$ kubectl apply -f ./authorizationpolicy-workload-allow-serviceaccount.yaml