Documentation
¶
Overview ¶
Package spiffe_identity is a Traefik local (Yaegi) middleware that turns a verified client certificate into a trusted identity header for the MCP gateway, and strips configured client-supplied headers before injection.
It runs at the TLS-terminating ingress for optional adapter certificates. Because Traefik terminates the caller's mTLS, this middleware is the only component that sees the caller's certificate; it extracts the SPIFFE URI SAN and injects it as the verified-identity header, then re-encrypts onward to the gateway. The strip-before-inject ordering is the load-bearing anti-spoofing guarantee: a client cannot smuggle its own verified header past this middleware.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Config ¶
type Config struct {
// VerifiedHeader is the header the gateway reads for the caller identity.
VerifiedHeader string `json:"verifiedHeader,omitempty"`
// TrustDomain, when set, restricts which SPIFFE host is accepted from the
// client certificate. Empty accepts any spiffe:// URI SAN (the gateway
// still validates the trust domain against policy).
TrustDomain string `json:"trustDomain,omitempty"`
// StripHeaders are client-supplied headers deleted on every request before
// the verified header is injected. The VerifiedHeader is always stripped in
// addition to this list.
StripHeaders []string `json:"stripHeaders,omitempty"`
// RejectInvalidCertificate rejects a presented client certificate without a
// SPIFFE URI SAN matching TrustDomain. Requests without a certificate pass.
RejectInvalidCertificate bool `json:"rejectInvalidCertificate,omitempty"`
}
Config holds the middleware configuration.
func CreateConfig ¶
func CreateConfig() *Config
CreateConfig returns the default plugin configuration.
type Middleware ¶
type Middleware struct {
// contains filtered or unexported fields
}
Middleware implements http.Handler.
func (*Middleware) ServeHTTP ¶
func (m *Middleware) ServeHTTP(rw http.ResponseWriter, req *http.Request)