handle custom sni in bootstrap clusters#26684
Merged
istio-testing merged 2 commits intoistio:masterfrom Aug 20, 2020
Merged
Conversation
Signed-off-by: Rama Chavali <rama.rao@salesforce.com>
Contributor
Author
hzxuzhonghu
approved these changes
Aug 20, 2020
Collaborator
|
In response to a cherrypick label: new pull request created: #26685 |
howardjohn
reviewed
Aug 20, 2020
| return nil | ||
| } | ||
| if len(sniName) > 0 { | ||
| if len(tls.Sni) == 0 && tls.Mode == networkingAPI.ClientTLSSettings_ISTIO_MUTUAL { |
Member
There was a problem hiding this comment.
why do we not set SNI for mutual or simple?
Contributor
Author
There was a problem hiding this comment.
for ISTIO_MUTUAL we default it to "tracer" , "envoy_metrics_service" if tls.Sni is not specified - that was the existing behaviour.
For Simple and Mutual we set it only if it is specified in TLS settings (because we do not know what to default to).
Are you suggesting we should not default for ISTIO_MUTUAL as well and only set if user sets it?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The TLS SNI check was in handled in correctly in PR #25070 for bootstrap clusters. This PR fixes it.
[ ] Configuration Infrastructure
[ ] Docs
[ ] Installation
[X ] Networking
[ ] Performance and Scalability
[ ] Policies and Telemetry
[ ] Security
[ ] Test and Release
[ ] User Experience
[ ] Developer Infrastructure
Pull Request Attributes
Please check any characteristics that apply to this pull request.
[ ] Does not have any changes that may affect Istio users.