Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions linkerd/app/inbound/src/detect.rs
Original file line number Diff line number Diff line change
Expand Up @@ -322,6 +322,18 @@ impl svc::Param<Remote<ServerAddr>> for Forward {
}
}

impl svc::Param<Remote<ClientAddr>> for Forward {
fn param(&self) -> Remote<ClientAddr> {
self.client_addr
}
}

impl svc::Param<tls::ConditionalServerTls> for Forward {
fn param(&self) -> tls::ConditionalServerTls {
self.tls.clone()
}
}

impl svc::Param<transport::labels::Key> for Forward {
fn param(&self) -> transport::labels::Key {
transport::labels::Key::inbound_server(
Expand Down
17 changes: 17 additions & 0 deletions linkerd/app/inbound/src/direct.rs
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ pub(crate) struct LocalTcp {
#[derive(Debug, Clone)]
pub(crate) struct AuthorizedLocalTcp {
addr: Remote<ServerAddr>,
client_addr: Remote<ClientAddr>,
client_id: tls::ClientId,
permit: policy::ServerPermit,
}
Expand Down Expand Up @@ -123,6 +124,7 @@ impl<N> Inbound<N> {
.push_map_target(|(permit, tcp): (policy::ServerPermit, LocalTcp)| {
AuthorizedLocalTcp {
addr: tcp.server_addr,
client_addr: tcp.client_addr,
client_id: tcp.client_id,
permit,
}
Expand Down Expand Up @@ -303,6 +305,21 @@ impl Param<Remote<ServerAddr>> for AuthorizedLocalTcp {
}
}

impl Param<Remote<ClientAddr>> for AuthorizedLocalTcp {
fn param(&self) -> Remote<ClientAddr> {
self.client_addr
}
}

impl Param<tls::ConditionalServerTls> for AuthorizedLocalTcp {
fn param(&self) -> tls::ConditionalServerTls {
tls::ConditionalServerTls::Some(tls::ServerTls::Established {
client_id: Some(self.client_id.clone()),
negotiated_protocol: None,
})
}
}

impl Param<transport::labels::Key> for AuthorizedLocalTcp {
fn param(&self) -> transport::labels::Key {
transport::labels::Key::inbound_server(
Expand Down
18 changes: 18 additions & 0 deletions linkerd/app/inbound/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ pub mod direct;
mod http;
mod metrics;
pub mod policy;
mod proxy_protocol;
mod server;

#[cfg(any(test, feature = "test-util", fuzzing))]
Expand All @@ -34,6 +35,7 @@ use linkerd_app_core::{
transport::{self, Remote, ServerAddr},
Error, NameAddr, NameMatch, ProxyRuntime,
};
use rangemap::RangeInclusiveSet;
use std::{fmt::Debug, time::Duration};
use thiserror::Error;

Expand All @@ -57,6 +59,22 @@ pub struct Config {

/// Enables unsafe authority labels.
pub unsafe_authority_labels: bool,

/// Ports on which the proxy prepends a HAProxy PROXY protocol v2 header
/// (carrying the real client address and, when available, its verified
/// mTLS identity) to the TCP connection opened to the local application.
///
/// This only applies to the opaque/TCP forwarding path; HTTP connections
/// proxied by this process never carry this header.
pub proxy_protocol_v2_ports: RangeInclusiveSet<u16>,

/// Ports on which the proxy prepends a HAProxy PROXY protocol v1 (text)
/// header to the TCP connection opened to the local application, for
/// applications that do not support v2. Version 1 carries the client
/// address only; it cannot carry the client identity.
///
/// Must not overlap with `proxy_protocol_v2_ports`.
pub proxy_protocol_v1_ports: RangeInclusiveSet<u16>,
}

#[derive(Clone)]
Expand Down
Loading