diff options
author | Stephen Wong <stephen.kf.wong@gmail.com> | 2018-09-19 20:52:46 +0000 |
---|---|---|
committer | Gerrit Code Review <gerrit@opnfv.org> | 2018-09-19 20:52:46 +0000 |
commit | e8eaf48f2a1230658e38eb8d609bdcd31b3661fd (patch) | |
tree | 7e2f35c48cfbcb5d082a3374fc6fc9880f0b375d /samples/scenarios/ingressgateway_ext_authz_filter.yaml | |
parent | edc329733d16a2df409ddfc34f1fae52e875ffd6 (diff) | |
parent | 0ade6b1a529828c72d68ae2c42d17a33dd61586e (diff) |
Merge "Add ModSecurity config guide"
Diffstat (limited to 'samples/scenarios/ingressgateway_ext_authz_filter.yaml')
-rw-r--r-- | samples/scenarios/ingressgateway_ext_authz_filter.yaml | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/samples/scenarios/ingressgateway_ext_authz_filter.yaml b/samples/scenarios/ingressgateway_ext_authz_filter.yaml new file mode 100644 index 0000000..0960a50 --- /dev/null +++ b/samples/scenarios/ingressgateway_ext_authz_filter.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.istio.io/v1alpha3 +kind: EnvoyFilter +metadata: + name: ext-authz + namespace: clover-gateway +spec: + workloadLabels: + app: istio-ingressgateway + filters: + - insertPosition: + index: FIRST + listenerMatch: + portNumber: 80 + listenerType: GATEWAY + listenerProtocol: HTTP + filterType: HTTP + filterName: "envoy.ext_authz" + filterConfig: + http_service: + server_uri: + uri: "http://modsecurity-crs.clover-gateway.svc.cluster.local" + cluster: "outbound|80||modsecurity-crs.clover-gateway.svc.cluster.local" + timeout: 0.5s + failure_mode_allow: false |