如何在Envoy Proxy中配置支持公共访问的Web API
解决方法
你只需要调整envoy.filters.http.jwt_authn过滤器下的rules规则顺序,新增一条公共API路径的白名单规则即可。Envoy的JWT认证规则遵循从上到下优先匹配逻辑,匹配到靠前的规则后不会继续校验后续规则。
调整后的完整配置
http_filters: - name: envoy.filters.http.grpc_http1_bridge typed_config: {} - name: envoy.filters.http.cors typed_config: {} - name: envoy.filters.http.jwt_authn typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication providers: identity_api: issuer: 'null' audiences: - apigw forward: true remote_jwks: http_uri: uri: http://abc.identity.api/.well-known/openid-configuration/jwks cluster: identity_api timeout: 1s cache_duration: seconds: 30 from_headers: - name: Authorization value_prefix: "Bearer " rules: # 新增公共接口白名单规则,放在所有规则最前面 - match: prefix: /v1/fares/locations/location # 空require代表无需JWT校验,直接放行 requires: {} - match: { prefix: /v1/newhubs/ } - match: { prefix: / } requires: provider_name: identity_api - name: envoy.filters.http.ext_authz typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthz transport_api_version: V3 grpc_service: envoy_grpc: cluster_name: permissions_api_grpc timeout: 3s with_request_body: max_request_bytes: 819200 allow_partial_message: true - name: envoy.filters.http.router typed_config: {}
配置说明
- 路径匹配仅校验URI的path部分,query参数(比如示例中的
?searchTerm=ABC)不会影响匹配结果,该规则对所有同路径的请求都会生效 - 如需开放
/v1/fares/路径下的所有接口作为公共接口,直接将prefix值修改为/v1/fares/即可 - 白名单规则必须放在全局匹配
prefix: /的规则之前,否则会被全局JWT校验规则覆盖
注意:如果你的后续
ext_authz外部鉴权过滤器也需要对该公共接口放行,需要额外在ext_authz配置中添加路径白名单规则,否则该接口仍会被外部鉴权逻辑拦截。
内容的提问来源于stack exchange,提问作者Khaan
相关产品推荐
相关产品推荐

