fluent / fluent/fluentd

Ability to inject mtls client cert subject info

Open
#3,537 0 comments 2 reactions 0 assignees View on GitHub
enhancement
Dominant language
Ruby
Stars
13.6k
Forks
1.4k
Avg merge
1d 3h
Merged PRs (30d)
20

Description

### Is your feature request related to a problem? Please describe.

I have successfully set up communication between a fluentbit instance running forward on my edge and a mTLS-capable receiver fluentd instance running forward up in the cloud. I have TLS verification working fine after trusting our private CA chain. But I want to potentially tag data or inject keys in to it describing the subject of the certificate. That way, I could, for instance, put records in different elasticsearch instances based on the client certificate this record came from.

### Describe the solution you'd like

Like `source_address_key` in the [forward input](https://docs.fluentd.org/input/forward), something like `client_certificate_subject_key` would be great. Subject, some hash id of the cert...some identifying information.

### Describe alternatives you've considered

I suppose I can still use the username system, but that seems to be a bit redundant. The client certificate should be enough to uniquely authenticate my end users.

### Additional context

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.