envoyproxy / envoyproxy/envoy

FR: nested network filter chains

Open
#18,035 11 comments 2 reactions 0 assignees View on GitHub
area/listener design proposal help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 20h
Merged PRs (30d)
437

Description

Currently, listener inspectors and transport sockets are forced to reside at one-level: first inspect, then match, then use a transport socket. This is quite inflexible, and leads to situations where a whole expensive listener is needed (e.g. https://github.com/envoyproxy/envoy/issues/4076). The proposal is to add a oneof that allows (inspectors + filter chains) to reside within the filter chains next to filters. The semantics is that processing is staged where once a filter chain is selected, transport socket is applied, and then inspector + filter chain matching restart.

This solves a bunch of issues:
1. Proxy protocol can be placed within TLS on server-side.
2. TLS-within-TLS can be matched provided outer TLS is prior knowledge.
3. HTTP-within-TLS can be sniffed provided outer TLS is prior knowledge.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.