Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Client tls proxy #920

Merged
merged 10 commits into from
Dec 9, 2019
Merged

Client tls proxy #920

merged 10 commits into from
Dec 9, 2019

Conversation

abhijitherekar
Copy link
Contributor

@abhijitherekar abhijitherekar commented Nov 14, 2019

Description

The L7 app proxy is not sending the client certificate for PU-to-PU workflow. This breaks:

  1. mtls between PU to PU on L7.
  2. Aporeto to Envoy PU http flow.

Fixes: https://github.com/aporeto-inc/aporeto/issues/2370

Test plan

Outline the test plan used to test this change before merging it.

Fixes #.

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "02e7dcb86543de2fcc77f581ebd82d18e61db6a6"
  },
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "61cf6753fa149fc43c54529083046731a4738ace"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "7a9fb2235d0fc8335dbbae78815abc84160d3020"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "02e7dcb86543de2fcc77f581ebd82d18e61db6a6"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "7a9fb2235d0fc8335dbbae78815abc84160d3020"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "02e7dcb86543de2fcc77f581ebd82d18e61db6a6"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "7a9fb2235d0fc8335dbbae78815abc84160d3020"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "b30028f46e7091af05d168345c4d83ab9f7c9a5c"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "ce252c11fa4d3cd07a4356c6e759c6c90886621c"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "b30028f46e7091af05d168345c4d83ab9f7c9a5c"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "47b2528c63ec3cb668b9f9ab8ce93fa163f938a9"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "b30028f46e7091af05d168345c4d83ab9f7c9a5c"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "3a01ad115473b093bb2f25a80a3de8cbb5a64406"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "b30028f46e7091af05d168345c4d83ab9f7c9a5c"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "b30028f46e7091af05d168345c4d83ab9f7c9a5c"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "9c8c8aeede8195bdba56b620870a99dd8784b0dc"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "f515685cb54cfc71c02756e18fa4e4f7948a5f55"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "71d869652e57fa89c24126aa32b822a0b77886d2"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "785ac8b1eeab7ddb0974e333a6d870b6141ac67a"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "73b25792c00750315d8a51f1d98c1d5f98130ca7"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "29add17bb18a50e7b5615d383fa3d14bf7750d83"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "c5954cb19d64c0849651577307f3b2cd9559f0ff"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "8687a6221a69324c7661f191446e5c45909bfbce"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "c5954cb19d64c0849651577307f3b2cd9559f0ff"
  }
]

@abhijitherekar
Copy link
Contributor Author

/build - automatically fired by gogo with following PRs and commit SHAs v1.0.0

[
  {
    "project": "AppProxy-client-config",
    "component": "trireme-lib",
    "pr-id": "920",
    "commit-sha": "a218f5e0ef549f1c1bd2c197dc5dad609c6e9973"
  },
  {
    "project": "AppProxy-client-config",
    "component": "enforcerd",
    "pr-id": "1502",
    "commit-sha": "c5954cb19d64c0849651577307f3b2cd9559f0ff"
  }
]

Copy link
Contributor

@mheese mheese left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good to me ... exactly as we tested and discussed how it has to be :shipit:

however, as this is a critical change, I want that @dstiliadis gives his thumbs up on this change as well

@@ -261,6 +294,7 @@ func (p *Config) RunNetworkServer(ctx context.Context, l net.Listener, encrypted
DialContext: networkDialerWithContext,
MaxIdleConnsPerHost: 2000,
MaxIdleConns: 2000,
ForceAttemptHTTP2: true,
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the force is done for the golang issue: golang/go#21336

@abhijitherekar abhijitherekar merged commit 265b63b into master Dec 9, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants