This repository has been archived by the owner on Jul 11, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 276
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Introducing per-service filtering (#1725)
Introducing per-service filtering Introduces per-destination filter-chain matching on outbound. This change will allow setting specific L4 or L7 filtering, precursor for TCP routing. - Since we are filtering all permitted traffic, we can generalize the remaining traffic and simplify Egress, which will not require a CIDR anymore. (TODO: cleanup CIDR flags/code) - Since we can match all destination traffic, Permissive mode can potentially use TCP proxy if we want (instead of wildcarded RDS) to allow also L4 protocols between services. - Additional work that might benefit from it: per-service route table on RDS, TCP routing, .... Additionally: - Fixing the listener tests required adding the long-awaited catalog mock. Will add more tests in subsequent commits.
- Loading branch information
Showing
10 changed files
with
499 additions
and
162 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.