This message was deleted.
# general
s
This message was deleted.
a
This seems perpendicualr to Pulsar in a way. Have you thought to centralize all changes via a central component and have it generate change events?
h
@Asaf Mesika We have a manifest importer service that is exposed to our customers. They can make changes to their manifest there and a successful merge/pull request will enable a pipeline to deploy those changes to pulsar. The question that our security team is asking, is how will we know if manifest changes in Pulsar. If an actor were to change the permissions on a topic say, how would the pulsar admin team know? I’m wondering if the community has thought through any of these issues.
d
cc @David K @Marshall Portwood
m
Like Asaf said, yo ucan utilize something like FluxCD which does automatic reconciliation of the helm charts and automatic sync of properties across pulsar clusters to be consistent using flux deployment configuration.
a
How about making that importer the only one using a certain user and that user is the only one with the permissions to do so?
Another option, which is commercial is StreamNative Audit plugin. It creates messages for events in Pulsar like creating topic / etc. You can contact SN to get more details.