5 ms·
I'm curious how you're doing authorization in Envoy. Is it a JWT-based httpfilter?
by ipsin 8y ago
I'm curious how you're doing authorization in Envoy. Is it a JWT-based httpfilter?
- SirMonkey 8y agoThe funny thing with envoy is that you can take the source of the authz service and build your own auth-mechanism for other protocols. We are doing that for MQTT
- buckhx 8y agoCan't speak for OP, but we have a similar stack and use middleware on the actual services since they need to decide which permissions are needed instead of centralized auth at the gateway level.
- nzoschke 8y agoOP here. We use the envoy authz filter. For every incoming request envoy first calls out to a custom auth check service with all the request metadata like path and http headers. The auth service can return a “fail” response which indicates to not forward the original request any further. Or it can return a “pass” response plus data to add to the original request headers. Docs here: https://www.envoyproxy.io/docs/envoy/latest/configuration/http_filters/ext_authz_filter https://www.envoyproxy.io/docs/envoy/latest/configuration/ht...