spiffe_identity

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package spiffe_identity is a Traefik local (Yaegi) middleware that turns a verified client certificate into a trusted identity header for the MCP gateway, and strips configured client-supplied headers before injection.

It runs at the TLS-terminating ingress for optional adapter certificates. Because Traefik terminates the caller's mTLS, this middleware is the only component that sees the caller's certificate; it extracts the SPIFFE URI SAN and injects it as the verified-identity header, then re-encrypts onward to the gateway. The strip-before-inject ordering is the load-bearing anti-spoofing guarantee: a client cannot smuggle its own verified header past this middleware.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func New

func New(_ context.Context, next http.Handler, cfg *Config, _ string) (http.Handler, error)

New creates the middleware.

Types

type Config

type Config struct {
	// VerifiedHeader is the header the gateway reads for the caller identity.
	VerifiedHeader string `json:"verifiedHeader,omitempty"`
	// TrustDomain, when set, restricts which SPIFFE host is accepted from the
	// client certificate. Empty accepts any spiffe:// URI SAN (the gateway
	// still validates the trust domain against policy).
	TrustDomain string `json:"trustDomain,omitempty"`
	// StripHeaders are client-supplied headers deleted on every request before
	// the verified header is injected. The VerifiedHeader is always stripped in
	// addition to this list.
	StripHeaders []string `json:"stripHeaders,omitempty"`
	// RejectInvalidCertificate rejects a presented client certificate without a
	// SPIFFE URI SAN matching TrustDomain. Requests without a certificate pass.
	RejectInvalidCertificate bool `json:"rejectInvalidCertificate,omitempty"`
}

Config holds the middleware configuration.

func CreateConfig

func CreateConfig() *Config

CreateConfig returns the default plugin configuration.

type Middleware

type Middleware struct {
	// contains filtered or unexported fields
}

Middleware implements http.Handler.

func (*Middleware) ServeHTTP

func (m *Middleware) ServeHTTP(rw http.ResponseWriter, req *http.Request)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL