Uploaded image for project: 'Maistra'
  1. Maistra
  2. MAISTRA-2665

OSSM 2.1 performance: kind RequestAuthentication and AuthorizationPolicy take long time to complete configuration

    XMLWordPrintable

Details

    • Bug
    • Resolution: Obsolete
    • Major
    • None
    • maistra-2.1.0
    • None
    • None
    • False
    • False

    Description

      OSSM 2.0 and 2.1 kind RequestAuthentication and AuthorizationPolicy take long time to complete configuration.
      When I test ossm security authorization test cases : JWT token[1] and Explicit Deny[2], each policy apply or change needs 30-60 seconds to complete in a mesh.

      Reference:
      1. https://istio.io/v1.9/docs/tasks/security/authorization/authz-jwt/
      2. https://istio.io/v1.9/docs/tasks/security/authorization/authz-deny/

      How to reproduce:
      1. Install ossm and smcp on an OCP cluster
      2. Follow Ref [1] and [2]
      https://istio.io/v1.9/docs/tasks/security/authorization/authz-jwt/#allow-requests-with-valid-jwt-and-list-typed-claims
      and
      https://istio.io/v1.9/docs/tasks/security/authorization/authz-deny/#explicitly-deny-a-request
      takes 40+ seconds and then we can verify the results

      Expected Behavior :
      Authorization policy changes should have a better performance and reduce the wait time.

      Attachments

        Activity

          People

            Unassigned Unassigned
            yuaxu@redhat.com Yuanlin Xu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: