envoyproxy / envoyproxy/envoy

ext-authz cannot be used with DNS.

Open
#4,637 9 comments 0 reactions 1 assignee Claimed by @gsagula View on GitHub
area/ext_authz bug help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 22h
Merged PRs (30d)
430

Description

**Issue Template**

*Title*: *ext-authz cannot be used with DNS.*

*Description*:
>When using a statically configured ext-authz cluster that has a cluster type of STRICT_DNS or LOGICAL_DNS the ext-authz filter will use the incoming host header for routing requests. This is problematic because if the wrong host is selected during routing traffic will flow to a cluster that may return 200 and allow traffic through where it shouldn't.

*Repro steps*:
- Statically configure a cluster for accepting ext-authz traffic. This cluster must use DNS as its cluster type.
- Configure any routes (ex: "foo.local", "bar.local")
- send requests to "foo.local". Requests intended for auth.local will instead be routed to `foo.local`.

*Config*:
```
filters:
- name: envoy.ext_authz
stat_prefix: ext_authz
grpc_service:
envoy_grpc:
cluster_name: ext-authz

clusters:
- name: ext-authz
type: STRICT_DNS
http2_protocol_options: {}
hosts:
- socket_address: { address: auth.local, port_value: 80 }
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.