envoyproxy/envoy

FR: nested network filter chains

開放

#18,035 建立於 2021年9月9日

 (11 則留言) (2 個反應) (0 位負責人)C++ (5,373 個分叉)batch import
area/listenerdesign proposalhelp wanted

倉庫指標

星標
 (27,997 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Currently, listener inspectors and transport sockets are forced to reside at one-level: first inspect, then match, then use a transport socket. This is quite inflexible, and leads to situations where a whole expensive listener is needed (e.g. https://github.com/envoyproxy/envoy/issues/4076). The proposal is to add a oneof that allows (inspectors + filter chains) to reside within the filter chains next to filters. The semantics is that processing is staged where once a filter chain is selected, transport socket is applied, and then inspector + filter chain matching restart.

This solves a bunch of issues:

  1. Proxy protocol can be placed within TLS on server-side.
  2. TLS-within-TLS can be matched provided outer TLS is prior knowledge.
  3. HTTP-within-TLS can be sniffed provided outer TLS is prior knowledge.

貢獻者指南