https://www.ory.sh/ logo
c

colossal-whale-56336

04/11/2022, 5:52 PM
Is there any way I can make a session, a cookie value for that session and set it only whilst using Kratos as an API? We're trying to transition parts of our system to use Kratos as an identity provider whilst maintaining the same API we give to our frontend developers
h

high-optician-2097

04/11/2022, 5:57 PM
That's unfortunately not possible at the moment - but we're thinking about different options. Thing is though that it's kinda tricky from a security perspective. We'll have to do some soul searching 😂
c

colossal-whale-56336

04/11/2022, 5:58 PM
Ahh ok, also what are we supposed to do to "secure" the admin api? Are we supposed to use mTLS or something to ensure the someone in the network is authenticated?
h

high-optician-2097

04/11/2022, 6:09 PM
whatever you seem fit for your use case! in ory cloud we use istio with cilium and api keys
3 Views