Skip to content

Router authn/z part 2: ate-setup: add --ingress-auth-mode - #2388

Draft
Taahir Ahmed (ahmedtd) wants to merge 2 commits into
agent-substrate:mainfrom
ahmedtd:router-authnz-2
Draft

Taahir Ahmed (ahmedtd) wants to merge 2 commits into
agent-substrate:mainfrom
ahmedtd:router-authnz-2

Conversation

@ahmedtd

@ahmedtd Taahir Ahmed (ahmedtd) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked over #2387

Add --ingress-auth-mode to ate-setup, to pick between static-mtls and insecure modes for the ingress router.

By default, static-mtls mode is set up to trust certificates issued by podidentity.podcert.ate.dev/identity, which is the most convenient option for setups running within the scope of a single cluster.

…router

Add --ingress-auth-mode=:{static-mtls|insecure}.

In static-mtls all clients must present a SPIFFE certificate (validated
with --ingress-client-ca-file).  The SPIFFE ID is checked against an
allowlist (in --ingress-allowed-spiffe-ids).

In static-mtls mode, the router will refuse to start with a plaintext
listener.
Add --ingress-auth-mode to ate-setup, to pick between static-mtls and
insecure modes for the ingress router.

By default, static-mtls mode is set up to trust certificates issued by
podidentity.podcert.ate.dev/identity, which is the most convenient
option for setups running within the scope of a single cluster.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant