Role Based Access Control (RBAC) Network Filter

The RBAC network filter is used to authorize actions (permissions) by identified downstream clients (principals). This is useful to explicitly manage callers to an application and protect it from unexpected or forbidden agents. The filter supports configuration with either a safe-list (ALLOW) or block-list (DENY) set of policies based on properties of the connection (IPs, ports, SSL subject). This filter also supports policy in both enforcement and shadow modes. Shadow mode won’t effect real users, it is used to test that a new set of policies work before rolling out to production.

  • v2 API reference
  • This filter should be configured with the name envoy.filters.network.rbac.

Statistics

The RBAC network filter outputs statistics in the .rbac. namespace.

NameTypeDescription
allowedCounterTotal requests that were allowed access
deniedCounterTotal requests that were denied access
shadow_allowedCounterTotal requests that would be allowed access by the filter’s shadow rules
shadow_deniedCounterTotal requests that would be denied access by the filter’s shadow rules

Dynamic Metadata

The RBAC filter emits the following dynamic metadata.

NameTypeDescription
shadow_effective_policy_idstringThe effective shadow policy ID matching the action (if any).
shadow_engine_resultstringThe engine result for the shadow rules (i.e. either allowed or denied).