envoyproxy / envoyproxy/gateway
Support for Forward Auth
- Dominant language
- Go
- Stars
- 3k
- Forks
- 864
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 140
Description
## Description:
I was very impressed by Envoy Gateway at kubecon last week, and is looking into if we can migrate to it from ingress-nginx!
We are heavy users of oauth2proxy running as a service, by utilizing ingress-nginx forward auth.
It works by forwarding all requests to oauth2proxy, and if it responds with a 2xx the request is authorized and can continue to its original destination.
If the user is not authorized it will respond with a 302 that will redirect the user to a login endpoint (in our case Azure Entra ID), and after completion redirect to oauth2proxy, that will store a cookie and redirect the user back to the original target endpoint.
It is very important that all responses from oauth2proxy that is not a 2xx response should be sent to the user.
## Relevant links:
Similar to this, https://github.com/envoyproxy/gateway/issues/4562, but it seems they are running as Oauth2proxy as a proxy while we are using it as a `middleware`
### oauth2proxy

https://oauth2-proxy.github.io/oauth2-proxy/
### Traefik
This is also how Traefik handles ForwardAuth - https://doc.traefik.io/traefik/middlewares/http/forwardauth/

Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.