envoyproxy / envoyproxy/gateway

Could we loose Backend endpoints IP loopback validation ?

Open
#5,058 9 comments 0 reactions 0 assignees View on GitHub
stale triage
Dominant language
Go
Stars
3k
Forks
864
Avg merge
2d 2h
Merged PRs (30d)
140

Description

*Description*:
>Describe the desired behavior, what scenario it enables and how it
would be used.

Hi, we are using Envoy Gateway (EG) to manage traffic between our on-prem and public cloud services. However, in our internal network setup, we have a restriction that disable direct access to public cloud environments without routing traffic through an internal HTTP proxy.

The traffic flow is
client->envoy->[proxy2]->exampleorg.com

The issue is similar to https://github.com/envoyproxy/envoy/issues/21175, where a loopback is required for tcp tunneling. We follow their solution to reach public cloud services.

After we upgrade EG, we find that the Backends IP loopback validation is added https://github.com/envoyproxy/gateway/blob/main/internal/gatewayapi/backend.go#L61-L63 which prevents us to create a loopback backend. Could we loose the Backend endpoints IP loopback validation ?

Your advice would be greatly appreciated.
Thank you!

[optional *Relevant Links*:]
>Any extra documentation required to understand the issue.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.