Commit 23ccb7a
authored
Allow cluster names in Cofide identities (#97)
* chore: Allow cluster names in Cofide identities
Closes #96
Removes the regex validation of the SPIFFE IDs for access to the Connect
API. Envoy will still validate the presented cert, but then which
identities can do what is handled within Connect application code.
On the xds service the validation remains to only allow the Cofide agent
to connect to it, but the regex is updated to allow SPIFFE IDs both with
and without cluster names in them. Once Connect is updated to always
include the cluster name in this identity the old one can be removed.1 parent cf1ba8c commit 23ccb7a
File tree
2 files changed
+18
-31
lines changed- charts/cofide-connect
- templates
2 files changed
+18
-31
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
| 51 | + | |
51 | 52 | | |
52 | 53 | | |
53 | 54 | | |
54 | | - | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
55 | 61 | | |
56 | 62 | | |
57 | 63 | | |
| |||
224 | 230 | | |
225 | 231 | | |
226 | 232 | | |
227 | | - | |
228 | | - | |
229 | | - | |
230 | | - | |
231 | | - | |
232 | | - | |
233 | | - | |
234 | | - | |
235 | | - | |
236 | | - | |
237 | | - | |
238 | | - | |
239 | | - | |
240 | | - | |
241 | | - | |
242 | | - | |
243 | | - | |
244 | | - | |
245 | | - | |
246 | | - | |
247 | | - | |
248 | | - | |
249 | | - | |
250 | | - | |
251 | | - | |
252 | | - | |
253 | | - | |
254 | | - | |
255 | | - | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
256 | 243 | | |
257 | 244 | | |
258 | 245 | | |
| |||
0 commit comments