Skip to content

Commit

Permalink
Use HTTP1.1 to connect to upstream jwks endpoint (envoyproxy#977)
Browse files Browse the repository at this point in the history
Use HTTP1.1 to connec to upstream jwks endpoint

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
  • Loading branch information
arkodg authored Feb 4, 2023
1 parent 4a04915 commit 82e7672
Show file tree
Hide file tree
Showing 5 changed files with 4 additions and 30 deletions.
9 changes: 4 additions & 5 deletions internal/xds/translator/authentication.go
Original file line number Diff line number Diff line change
Expand Up @@ -219,11 +219,10 @@ func buildClusterFromJwks(jwks *jwksCluster) (*cluster.Cluster, error) {
},
},
},
TypedExtensionProtocolOptions: buildTypedExtensionProtocolOptions(),
DnsRefreshRate: durationpb.New(30 * time.Second),
RespectDnsTtl: true,
DnsLookupFamily: cluster.Cluster_V4_ONLY,
TransportSocket: tSocket,
DnsRefreshRate: durationpb.New(30 * time.Second),
RespectDnsTtl: true,
DnsLookupFamily: cluster.Cluster_V4_ONLY,
TransportSocket: tSocket,
}, nil
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,11 +58,6 @@
trustedCa:
filename: /etc/ssl/certs/ca-certificates.crt
type: STATIC
typedExtensionProtocolOptions:
envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
'@type': type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
explicitHttpConfig:
http2ProtocolOptions: {}
- connectTimeout: 10s
dnsLookupFamily: V4_ONLY
dnsRefreshRate: 30s
Expand All @@ -87,8 +82,3 @@
trustedCa:
filename: /etc/ssl/certs/ca-certificates.crt
type: STATIC
typedExtensionProtocolOptions:
envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
'@type': type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
explicitHttpConfig:
http2ProtocolOptions: {}
Original file line number Diff line number Diff line change
Expand Up @@ -58,8 +58,3 @@
trustedCa:
filename: /etc/ssl/certs/ca-certificates.crt
type: STATIC
typedExtensionProtocolOptions:
envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
'@type': type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
explicitHttpConfig:
http2ProtocolOptions: {}
Original file line number Diff line number Diff line change
Expand Up @@ -97,8 +97,3 @@
trustedCa:
filename: /etc/ssl/certs/ca-certificates.crt
type: STATIC
typedExtensionProtocolOptions:
envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
'@type': type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
explicitHttpConfig:
http2ProtocolOptions: {}
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,3 @@
trustedCa:
filename: /etc/ssl/certs/ca-certificates.crt
type: STATIC
typedExtensionProtocolOptions:
envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
'@type': type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
explicitHttpConfig:
http2ProtocolOptions: {}

0 comments on commit 82e7672

Please sign in to comment.