envoyproxy / envoyproxy/gateway

Validate String Formatter Values for HTTPRoute

Open
#7,192 4 comments 1 reaction 0 assignees View on GitHub
help wanted kind/bug
Dominant language
Go
Stars
3k
Forks
864
Avg merge
2d 2h
Merged PRs (30d)
140

Description

*Description*:

Envoy Gateway Control Plane will push bad HTTPRoute configurations to the Data Plane, wherein it gets rejected affecting all configuration.

*Repro steps*:

Add this to any HTTPRoute

```
filters:
- requestHeaderModifier:
add:
- name: X-Real-IP
value: '%REQ(X-Real-IP?x-client-ip?CF-Connecting-IP)%'
- name: X-Request-Start
value: t=%START_TIME(%s.%6f)%
type: RequestHeaderModifier
```

Monitor the Control Plane logs. You should see something like

```
envoy-gateway-78757f47d7-hnww7 envoy-gateway 2025-10-10T23:56:03.409Z ERROR xds-server cache/snapshotcache.go:346 Envoy rejected the last update with code 13 and message More than 1 alternative header specified in token: X-Real-IP?x-client-ip?CF-Connecting-IP
```

Also note the `Accepted` status on the HTTPRoute CRD

```
Status:
Parents:
Conditions:
Last Transition Time: 2025-10-10T23:56:03Z
Message: Route is accepted
Observed Generation: 49
Reason: Accepted
Status: True
Type: Accepted
Last Transition Time: 2025-10-10T23:56:03Z
Message: Resolved all the Object references for the Route
Observed Generation: 49
Reason: ResolvedRefs
Status: True
Type: ResolvedRefs
Controller Name: gateway.envoyproxy.io/gatewayclass-controller
```

*Environment*:

Envoy Gateway Version: 1.4.0

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.