You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Envoy Proxy中配置支持公共访问的Web API

解决方法

你只需要调整envoy.filters.http.jwt_authn过滤器下的rules规则顺序,新增一条公共API路径的白名单规则即可。Envoy的JWT认证规则遵循从上到下优先匹配逻辑,匹配到靠前的规则后不会继续校验后续规则。

调整后的完整配置

http_filters:
  - name: envoy.filters.http.grpc_http1_bridge
    typed_config: {}
  - name: envoy.filters.http.cors
    typed_config: {}
  - name: envoy.filters.http.jwt_authn
    typed_config:
      "@type": type.googleapis.com/envoy.extensions.filters.http.jwt_authn.v3.JwtAuthentication
      providers:
        identity_api:
          issuer: 'null'
          audiences:
          - apigw
          forward: true
          remote_jwks:
            http_uri:
              uri: http://abc.identity.api/.well-known/openid-configuration/jwks
              cluster: identity_api
              timeout: 1s   
            cache_duration:
              seconds: 30
          from_headers:
          - name: Authorization
            value_prefix: "Bearer "
      rules:
      # 新增公共接口白名单规则,放在所有规则最前面
      - match: 
          prefix: /v1/fares/locations/location
        # 空require代表无需JWT校验,直接放行
        requires: {}
      - match: { prefix: /v1/newhubs/ }
      - match: { prefix: / }
        requires:
          provider_name: identity_api
  - name: envoy.filters.http.ext_authz
    typed_config:
      "@type": type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthz
      transport_api_version: V3
      grpc_service:
        envoy_grpc:
          cluster_name: permissions_api_grpc
        timeout: 3s
      with_request_body:
        max_request_bytes: 819200
        allow_partial_message: true
  - name: envoy.filters.http.router
    typed_config: {}

配置说明

  • 路径匹配仅校验URI的path部分,query参数(比如示例中的?searchTerm=ABC)不会影响匹配结果,该规则对所有同路径的请求都会生效
  • 如需开放/v1/fares/路径下的所有接口作为公共接口,直接将prefix值修改为/v1/fares/即可
  • 白名单规则必须放在全局匹配prefix: /的规则之前,否则会被全局JWT校验规则覆盖

注意:如果你的后续ext_authz外部鉴权过滤器也需要对该公共接口放行,需要额外在ext_authz配置中添加路径白名单规则,否则该接口仍会被外部鉴权逻辑拦截。


内容的提问来源于stack exchange,提问作者Khaan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 19:27:02