Skip to content

story: Add Portal (OpenMFP) on demand to a running installation #306

Description

@Perseus985

User Story

As a Platform Mesh operator,
I want to be able to roll out the Portal (OpenMFP) afterwards in any Platform Mesh variant,
so that resources can also be managed via a UI.

Acceptance Criteria

  • The Portal (OpenMFP) can be added to an already-running installation via Helm values.
  • The Portal can also be disabled again, returning the stack to API-only without affecting Core components.
  • All Core functionality (org/account lifecycle, RBAC/ReBAC, OIDC/Keycloak) is fully usable via the API without the Portal.
  • The procedure for adding the Portal afterwards is documented.
  •  Once the Portal is active, all existing resources (created earlier via the API) are visualized — no re-sync or recreation needed.

Parent Epic

#290

Additional Context

For use in the Opendefense Cloud, infrastructure will exist in several sizes (data centers, deployable/field, mobile).
We want to manage and operate all stacks — across their different sizes — in a uniform way.

We plan to start with a deliberately minimal configuration: a single-organization setup running on native Kubernetes RBAC only — without OpenFGA and therefore without ReBAC-based authorization. Identity and authentication will be handled by our own external IdP (OIDC) rather than a Platform Mesh-provided one. Despite this reduced footprint, we still require the Portal (OpenMFP) for visualization, so that operators can view and manage resources through a UI even in this lean, single-org, RBAC-only deployment.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions