Replies: 2 comments
-
|
cc @zhaohuabing |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Envoy Gateway delegates auth to Envoy filters: Basic Auth and IP allowlisting (via RBAC) are separate. You can get an AND by applying both (e.g., a SecurityPolicy that includes Basic Auth plus IP-based authorization). A true OR (“allow if IP is allowed OR creds are valid”) isn’t supported today without custom ext_authz logic. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I see that I can use https://gateway.envoyproxy.io/docs/tasks/security/basic-auth/ and https://gateway.envoyproxy.io/docs/tasks/security/restrict-ip-access/ to restrict the access to services.
But how can i achieve a combination of those two? I have these two scenarios: Allow users to access a service either by...
In
ingress-nginxI built them like this:1.
Beta Was this translation helpful? Give feedback.
All reactions