Make overload.premature_reset_total_stream_count runtime setting configurable #5847
Labels
area/operational
Issues or PRs about making Contour easier to operate as a production service.
good first issue
Denotes an issue ready for a new contributor, according to the "help wanted" guidelines.
help wanted
Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
kind/feature
Categorizes issue or PR as related to a new feature.
This is a parameter that can be tuned to help mitigate CVE-2023-44487
Envoy has a default value of 500 but users may want to tune this to prevent resource starvation during an attack.
This can probably be a new field that is configurable in the Contour ConfigMap/Config CRD on the Listener stanza
Originally posted by @sunjayBhatia in #5826 (comment)
The text was updated successfully, but these errors were encountered: