-
Feature
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
None
-
False
-
None
-
False
-
-
server: envoy is getting added to response header of knative service and need ways to remove it as security finding is blocking release of one of our customer.
[admin@bastion][09:40:34] ~ $ oc get ksvc
NAME URL LATESTCREATED LATESTREADY READY REASON
sample https://sample-hello.apps.osh4dev.tatrabanka.sk sample-00001 sample-00001 True
- Case reproduction:
[admin@bastion][09:44:21] ~ $ curl -s -D - -o /dev/null https://sample-hello.apps.osh4dev.tatrabanka.sk
HTTP/1.1 200 OK
accept-ranges: bytes
content-length: 1517
content-type: text/html
date: Mon, 13 May 2024 07:44:36 GMT
last-modified: Mon, 07 Jan 2019 10:18:28 GMT
x-envoy-upstream-service-time: 4
server: envoy
set-cookie: 5f7ec6d803ff56a625d47ddb20abf22a=67bbc0206e6812f6fa31cec82df0578f; path=/; HttpOnly
cache-control: private
Strict-Transport-Security: max-age=31536000; includeSubDomains
Ongoing Slack thread: https://redhat-internal.slack.com/archives/CF5ANN61F/p1716353064399079
Links for known issue: https://github.com/envoyproxy/envoy/issues/14421