envoyproxy / envoyproxy/gateway

Update CTP status to highlight that any TLS setting requires HTTPS to be enabled in the listener

Abierto
#3,083 1 comentario 0 reacciones 0 asignados Ver en GitHub
help wanted
Lenguaje dominante
Go
Estrellas
3k
Forks
864
Merge medio
2 d 2 h
PR fusionados (30 d)
140

Descripción

@jhouston1604

Looking at the listener configuration, none of those listeners are configured to use TLS.

Your gateway is defined like this:
```yaml
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: envoy-public
namespace: envoy-public
spec:
gatewayClassName: envoy-public
listeners:
- name: http
protocol: HTTP
port: 80
allowedRoutes:
namespaces:
from: All
- name: https
protocol: HTTP
port: 443
allowedRoutes:
namespaces:
from: All
```

Simply using port 443 doesn't transform the listener to a TLS enabled listener. You need to add a TLS section at the very least:

```yaml
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: envoy-public
namespace: envoy-public
spec:
gatewayClassName: envoy-public
listeners:
- name: http
protocol: HTTP
port: 80
allowedRoutes:
namespaces:
from: All
- name: https
protocol: HTTPS # The protocol needs to be HTTPS and not HTTP
port: 443
allowedRoutes:
namespaces:
from: All
tls: # This section is missing in the configuration files you listed above
certificateRefs: # The place where the server X.509 certificate can be found
- group: ""
kind: Secret
name: example-cert
mode: Terminate
```

Since TLS is not configured for any of the listeners, limiting the supported TLS version to 1.3 in a `ClientTrafficPolicy` doesn't really make any sense here.

_Originally posted by @liorokman in https://github.com/envoyproxy/gateway/issues/3060#issuecomment-2029849962_

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.