envoy.filters.http.ext_authz与envoy.ext_authz的区别及Istio场景等效性验证
envoy.filters.http.ext_authz and envoy.ext_authz Synonymous in Envoy/Istio? Great question! Let’s break this down clearly, with concrete reasoning and verification points:
Short Answer
Absolutely—in the context of HTTP filter configurations, envoy.ext_authz is a fully supported shorthand alias for envoy.filters.http.ext_authz. They’re functionally identical and will load the exact same external authorization filter implementation in Envoy (and by extension, Istio).
Detailed Breakdown
Here’s why this works and how to confirm it:
Envoy’s Built-in Filter Aliases
Envoy’s core team added shorthand names for popular filters to reduce configuration verbosity. For HTTP filters specifically, well-known filters like ext_authz get a shorter alias that drops theenvoy.filters.http.prefix.You can verify this directly in Envoy’s source code: The HTTP ext_authz filter registers both its fully qualified name and the
envoy.ext_authzshorthand during initialization. When Envoy parses your config, it maps both names to the same filter factory, so there’s no difference in behavior.Istio’s Compatibility
In an Istio mesh, both names work seamlessly whether you’re configuring external auth via:- An
AuthorizationPolicypointing to an external provider, or - An
EnvoyFilterto manually inject the filter into the HTTP chain.
Istio’s control plane recognizes both identifiers and translates them to the same Envoy configuration under the hood. You might even see the shorthand used in some Istio community examples, though official docs tend to prefer the full name for explicit clarity.
- An
Important Caveat: Context Is Key
The shorthand only works when you’re configuring an HTTP filter. If you tried to useenvoy.ext_authzin a non-HTTP context (though ext_authz is primarily an HTTP filter, so this is rare), Envoy wouldn’t recognize it. Stick to the full name if you’re ever unsure about the configuration context.
Code Verification
For the skeptical folks (we get it!), check Envoy’s filter registration logic: The HTTP ext_authz filter is registered with both names in the filter factory setup. This means Envoy treats envoy.ext_authz as a direct alias for the full envoy.filters.http.ext_authz name.
内容的提问来源于stack exchange,提问作者dippynark

