Kuma API Access Control
Kuma provide a simple access control to administrative actions executed on Kuma API Server (port 5681 by default).
Manage admin resources
Admin resources are Secret and GlobalSecret.
KUMA_ACCESS_STATIC_ADMIN_RESOURCES_USERSallows users to manage admin resources. Default ismesh-system:admin.KUMA_ACCESS_STATIC_ADMIN_RESOURCES_GROUPSallows groups to manage admin resources. Default ismesh-system:admin.
Generate dataplane token
KUMA_ACCESS_STATIC_GENERATE_DP_TOKEN_USERSallows users to generate dataplane token. Defaultmesh-system:admin.KUMA_ACCESS_STATIC_GENERATE_DP_TOKEN_GROUPSallows groups to generate dataplane token. Defaultmesh-system:admin.
Generate user token
KUMA_ACCESS_STATIC_GENERATE_USER_TOKEN_USERSallows users to generate user token. Defaultmesh-system:admin.KUMA_ACCESS_STATIC_GENERATE_USER_TOKEN_GROUPSallows groups to generate user token. Defaultmesh-system:admin.
