Istio JWT 验证:RequestAuthentication 与 AuthorizationPolicyapiVersion: security.istio.io/v1beta1 kind: RequestAuthentication metadata: name: jwt namespace: app spec: selector: matchLabels: app: api jwtRules: - issuer: https://auth.example.com/ jwksUri: https://auth.example.com/.well-known/jwks.json audiences: - api apiVersion: security.istio.io/v1beta1 kind: AuthorizationPolicy metadata: name: allow-jwt namespace: app spec: selector: matchLabels: app: api rules: - from: - source: requestPrincipals: [ "*" ] to: - operation: paths: [ "/api/" ] methods: [ "GET", "POST" ] when: - key: request.auth.audiences values: [ "api" ] 总结JWT 验证与基于受众的策略结合,可实现细粒度且高效的服务访问控制。

点赞(0) 打赏

评论列表 共有 0 条评论

暂无评论
立即
投稿

微信公众账号

微信扫一扫加关注

发表
评论
返回
顶部