envoyproxy / envoyproxy/envoy

supporting partial wildcards on server names for filter chain matches

Open
#11,906 11 comments 3 reactions 0 assignees View on GitHub
area/tls help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 22h
Merged PRs (30d)
430

Description

Currently, when doing a filter chain match on server names you cannot use a partial wildcard:

https://github.com/envoyproxy/envoy/blob/master/api/envoy/api/v2/listener/listener_components.proto#L126

From a very quick look at how the server names are looked up:

https://github.com/envoyproxy/envoy/blob/master/source/server/filter_chain_manager_impl.cc#L418

it seems like supporting this could be done without a huge perf impact.

We have a use case for this, which would allow us to split a bunch of vhost/route configs into their own chains. This would save us from having to support per route overrides for the filters that need to be globally disabled and only enabled
for some vhosts/routes.

Any reasons not to support this? Thoughts?

cc: @htuch @lambdai @lizan @fishcakez

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.