envoyproxy / envoyproxy/gateway

EnvoyExtensionPolicy targetRefs

Open
#8,845 13 comments 0 reactions 0 assignees View on GitHub
area/api kind/decision stale
Dominant language
Go
Stars
3k
Forks
864
Avg merge
2d 2h
Merged PRs (30d)
140

Description

I have three EnvoyExtensionPolicy resources, one from Platform Admin(target to Gateway), two from different teams(target to same HTTPRoute).
Today only one of them will be accepted, should EG accept them all?

```yaml
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
name: lua-per-gateway-1
namespace: default
spec:
targetRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: eg
lua:
- type: Inline
inline: |
function envoy_on_request(request_handle)
request_handle:headers():add("X-Lua-Filter", "applied-at-gateway-class")
request_handle:logInfo("Lua filter executed for hostname: " .. (request_handle:headers():get(":authority") or "unknown"))
end
function envoy_on_response(response_handle)
response_handle:headers():add("X-Lua-Response", "true")
end
---
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
name: lua-per-route-1
namespace: default
spec:
targetRefs:
- group: gateway.networking.k8s.io
kind: HTTPRoute
name: backend
lua:
- type: Inline
inline: |
function envoy_on_request(request_handle)
request_handle:headers():add("X-Lua-Filter", "applied-at-gateway-class")
request_handle:logInfo("Lua filter executed for hostname: " .. (request_handle:headers():get(":authority") or "unknown"))
end
function envoy_on_response(response_handle)
response_handle:headers():add("X-Lua-Response", "true")
end
---
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
name: lua-per-route-2
namespace: default
spec:
targetRefs:
- group: gateway.networking.k8s.io
kind: HTTPRoute
name: backend
lua:
- type: Inline
inline: |
function envoy_on_request(request_handle)
request_handle:headers():add("X-Lua-Filter", "applied-at-gateway-class")
request_handle:logInfo("Lua filter executed for hostname: " .. (request_handle:headers():get(":authority") or "unknown"))
end
function envoy_on_response(response_handle)
response_handle:headers():add("X-Lua-Response", "true")
end

```

the status of them:
```yaml
apiVersion: v1
items:
- apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
name: lua-per-gateway-1
namespace: default
spec:
lua:
- inline: |
function envoy_on_request(request_handle)
request_handle:headers():add("X-Lua-Filter", "applied-at-gateway-class")
request_handle:logInfo("Lua filter executed for hostname: " .. (request_handle:headers():get(":authority") or "unknown"))
end
function envoy_on_response(response_handle)
response_handle:headers():add("X-Lua-Response", "true")
end
type: Inline
targetRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: eg
- group: gateway.networking.k8s.io
kind: HTTPRoute
name: backend
status:
ancestors:
- ancestorRef:
group: gateway.networking.k8s.io
kind: Gateway
name: eg
namespace: default
conditions:
- lastTransitionTime: "2026-04-24T14:05:14Z"
message: Policy has been accepted.
observedGeneration: 2
reason: Accepted
status: "True"
type: Accepted
- lastTransitionTime: "2026-04-24T14:05:14Z"
message: 'This policy is being overridden by other envoyExtensionPolicies
for these routes: [default/backend]'
observedGeneration: 2
reason: Overridden
status: "True"
type: Overridden
controllerName: gateway.envoyproxy.io/gatewayclass-controller
- apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
name: lua-per-route-1
namespace: default
spec:
lua:
- inline: |
function envoy_on_request(request_handle)
request_handle:headers():add("X-Lua-Filter", "applied-at-gateway-class")
request_handle:logInfo("Lua filter executed for hostname: " .. (request_handle:headers():get(":authority") or "unknown"))
end
function envoy_on_response(response_handle)
response_handle:headers():add("X-Lua-Response", "true")
end
type: Inline
targetRefs:
- group: gateway.networking.k8s.io
kind: HTTPRoute
name: backend
status:
ancestors:
- ancestorRef:
group: gateway.networking.k8s.io
kind: Gateway
name: eg
namespace: default
conditions:
- lastTransitionTime: "2026-04-24T14:05:14Z"
message: Unable to target HTTPRoute backend, another EnvoyExtensionPolicy
has already attached to it
observedGeneration: 1
reason: Conflicted
status: "False"
type: Accepted
controllerName: gateway.envoyproxy.io/gatewayclass-controller
- apiVersion: gateway.envoyproxy.io/v1alpha1
kind: EnvoyExtensionPolicy
metadata:
name: lua-per-route-2
namespace: default
spec:
lua:
- inline: |
function envoy_on_request(request_handle)
request_handle:headers():add("X-Lua-Filter", "applied-at-gateway-class")
request_handle:logInfo("Lua filter executed for hostname: " .. (request_handle:headers():get(":authority") or "unknown"))
end
function envoy_on_response(response_handle)
response_handle:headers():add("X-Lua-Response", "true")
end
type: Inline
targetRefs:
- group: gateway.networking.k8s.io
kind: HTTPRoute
name: backend
status:
ancestors:
- ancestorRef:
group: gateway.networking.k8s.io
kind: Gateway
name: eg
namespace: default
conditions:
- lastTransitionTime: "2026-04-24T14:04:09Z"
message: Unable to target HTTPRoute backend, another EnvoyExtensionPolicy
has already attached to it
observedGeneration: 1
reason: Conflicted
status: "False"
type: Accepted
controllerName: gateway.envoyproxy.io/gatewayclass-controller
kind: List
metadata:
resourceVersion: ""
```

cc @envoyproxy/gateway-maintainers

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.