Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-10639

Support RHOAI on securing communication between Gateway and Authorino for AuthPolicy

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • RHOAI
    • None

      Short summary of findings:

      mTLS is not supported in current Gateway API CIO setup. Alternative approach by setting Authorino TLS and configuring istio to use TLS via DestinationRule does not work because Kuadrant is creating their own envoy Cluster to call the authorino service via EnvoyFilters and by that bypassing the istio created cluster the DestinationRule would effect.

      https://redhat.enterprise.slack.com/archives/C093F58KVNC/p1755810442285599?thread_ts=1755810442.285599&cid=C093F58KVNC

      Workaround in comment.

              aknutsen@redhat.com Aslak Knutsen
              aknutsen@redhat.com Aslak Knutsen
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: