envoyproxy / envoyproxy/envoy

Duplicate custom_cert_validator config is not shared across all users

Open
#38,693 2 comments 0 reactions 0 assignees View on GitHub
area/certificates area/configuration enhancement help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 20h
Merged PRs (30d)
428

Description

custom_cert_validator creates duplicate objects for every cluster / listener using it

*Description*:
A proxy processing 100+ clusters takes up to 10 seconds to start up because it has to reload the same custom_cert_validator config being used by all of them.

*Repro steps*:
Configure multiple clusters / listeners with the same custom_validator_config. Each one will be initialized with a unique copy of the config, and each unique copy will be fully processed independently.

*Config*:
This validation context being used by multiple clusters. You can see from the debug logs that it is being parsed N times.

```
validation_context:
custom_validator_config:
name: envoy.tls.cert_validator.spiffe
typed_config:
"@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.SPIFFECertValidatorConfig
trust_domains:
- name: example.org
trust_bundle:
filename: ""
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.