Details
-
Bug
-
Resolution: Obsolete
-
Major
-
None
-
maistra-2.1.0
-
None
-
None
-
False
-
False
Description
OSSM 2.0 and 2.1 kind RequestAuthentication and AuthorizationPolicy take long time to complete configuration.
When I test ossm security authorization test cases : JWT token[1] and Explicit Deny[2], each policy apply or change needs 30-60 seconds to complete in a mesh.
Reference:
1. https://istio.io/v1.9/docs/tasks/security/authorization/authz-jwt/
2. https://istio.io/v1.9/docs/tasks/security/authorization/authz-deny/
How to reproduce:
1. Install ossm and smcp on an OCP cluster
2. Follow Ref [1] and [2]
https://istio.io/v1.9/docs/tasks/security/authorization/authz-jwt/#allow-requests-with-valid-jwt-and-list-typed-claims
and
https://istio.io/v1.9/docs/tasks/security/authorization/authz-deny/#explicitly-deny-a-request
takes 40+ seconds and then we can verify the results
Expected Behavior :
Authorization policy changes should have a better performance and reduce the wait time.