-
Notifications
You must be signed in to change notification settings - Fork 5.3k
Closed as not planned
Labels
area/ext_authzarea/rbacdesign proposalNeeds design doc/proposal before implementationNeeds design doc/proposal before implementationstalestalebot believes this issue/PR has not been touched recentlystalebot believes this issue/PR has not been touched recently
Description
The design (https://shorturl.at/gkrM3) proposes to introduce a unified matching API for ext_authz and RBAC filter in order to support many complex access control scenarios and also simplify the matching code in Envoy.
This allows to support the following feature requests:
- ext_authz config per virtual host: ext_authz config per virtual host #11522
- rbac: support mixing allow/deny policies with precedence: rbac: support mixing allow/deny policies with precedence #9376
- and more use cases in the design doc.
@mattklein123 @htuch @lizan @rshriram @incfly @liminw , please let me know your thoughts and feel free to comment in the doc, thank you.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area/ext_authzarea/rbacdesign proposalNeeds design doc/proposal before implementationNeeds design doc/proposal before implementationstalestalebot believes this issue/PR has not been touched recentlystalebot believes this issue/PR has not been touched recently