envoyproxy / envoyproxy/gateway

OIDC SecurityPolicy: failed OIDC discovery returns HTTP 500 on all affected routes

Open
#9,235 1 comment 5 reactions 0 assignees View on GitHub
help wanted kind/enhancement
Dominant language
Go
Stars
3k
Forks
864
Avg merge
2d 2h
Merged PRs (30d)
140

Description

*Description*:

When a SecurityPolicy configures OIDC by specifying only the issuer (relying on automatic discovery of the remaining endpoints via the provider's `/.well-known/openid-configuration` document), a failure of that discovery step causes every HTTPRoute protected by that OIDC policy to return HTTP 500 directly.

On large, shared clusters where many routes reference the same issuer, a single discovery failure breaks hundreds of routes simultaneously.

*Repro steps*:

* Create one or more OIDC SecurityPolicy resources that specify only `provider.issuer` (no explicit authorizationEndpoint / tokenEndpoint), targeting HTTPRoutes.
* Cause OIDC discovery to fail — e.g. the IdP's `/.well-known/openid-configuration` is temporarily unreachable, returns a non-2xx, times out, or the issuer is briefly misconfigured.
* Send requests to any HTTPRoute covered by those policies.

*Environment*:

* Envoy Gateway version: 1.8.1
* Kubernetes version: v1.35.5

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.