4
Size: a a a
4
ID
4
apiVersion: authentication.istio.io/v1alpha1
kind: Policy
metadata:
name: ingressgateway
namespace: istio-system
spec:
targets:
- name: istio-ingressgateway
peers:
- mtls: {}
origins:
- jwt:
audiences:
- "fd71d6b1-5728-4f8a-b38a-4ae4f89851e2"
issuer: "issuer"
jwksUri: "url"
jwtParams:
- id_token
jwtHeaders:
- Authorization
trigger_rules:
- excluded_paths:
- exact: /favicon.ico
- prefix: /login
- prefix: /static
- prefix: /stub
- prefix: /api
principalBinding: USE_ORIGIN
AK
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
name: some-policy
namespace: staging
spec:
{}
bectl apply м
анифест, все создано/сконфигурировано, но запросы на поды спокойно идут. ID
apiVersion: security.istio.io/v1beta1
kind: AuthorizationPolicy
metadata:
name: some-policy
namespace: staging
spec:
{}
bectl apply м
анифест, все создано/сконфигурировано, но запросы на поды спокойно идут. action: DENY
rules:
- from:
- source:
notRequestPrincipals: ["*"]
AK
action: DENY
rules:
- from:
- source:
notRequestPrincipals: ["*"]
ID
AK
AK
AK
ID
AK
AK
ID
AK
ID
ID
AK
AK
action: DENY
rules:
- from:
- source:
notRequestPrincipals: ["*"]