consul/proto/private
Paul Glass 77ecff3209
Permissive mTLS (#17035)
This implements permissive mTLS , which allows toggling services into "permissive" mTLS mode.
Permissive mTLS mode allows incoming "non Consul-mTLS" traffic to be forward unmodified to the application.

* Update service-defaults and proxy-defaults config entries with a MutualTLSMode field
* Update the mesh config entry with an AllowEnablingPermissiveMutualTLS field and implement the necessary validation. AllowEnablingPermissiveMutualTLS must be true to allow changing to MutualTLSMode=permissive, but this does not require that all proxy-defaults and service-defaults are currently in strict mode.
* Update xDS listener config to add a "permissive filter chain" when MutualTLSMode=permissive for a particular service. The permissive filter chain matches incoming traffic by the destination port. If the destination port matches the service port from the catalog, then no mTLS is required and the traffic sent is forwarded unmodified to the application.
2023-04-19 14:45:00 -05:00
..
pbacl Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbautoconf Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbcommon Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbconfig Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbconfigentry Permissive mTLS (#17035) 2023-04-19 14:45:00 -05:00
pbconnect Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbdemo Resource `Write` endpoint (#16786) 2023-04-06 10:40:04 +01:00
pboperator Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbpeering Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbpeerstream Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00
pbservice Permissive mTLS (#17035) 2023-04-19 14:45:00 -05:00
pbstatus Protobuf Refactoring for Multi-Module Cleanliness (#16302) 2023-02-17 16:14:46 -05:00
pbstorage Raft storage backend (#16619) 2023-04-04 17:30:06 +01:00
pbsubscribe Add PrioritizeByLocality to config entries. (#17007) 2023-04-14 15:42:54 -05:00
prototest Copyright headers for missing files/folders (#16708) 2023-03-28 18:48:58 -04:00