Skip to content

Conversation

ikethecoder
Copy link
Member

@ikethecoder ikethecoder commented Nov 14, 2024

@ikethecoder ikethecoder removed the wip label Nov 15, 2024
@ikethecoder ikethecoder marked this pull request as ready for review November 15, 2024 02:24
Copy link
Contributor

@rustyjux rustyjux left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Some docs that would be nice to see alongside this:

  • something in infra doc/ops outlining the upstream namespace restrictions capability (basically what you have in the issue description)
  • what data planes we are using upstream validation on (is this the plan for Emerald?)
  • updates to client tech docs to let them know about this requirement on relevant DPs.

I also wonder how possible it would be to resolve the deserialized data CodeQL alert? Or is it also a false positive?

Alas I'd also tweaked mock_keycloak to have a ns with different perm-domains for custom certs tests so I'll need to do a little conflict resolution there.

@ikethecoder ikethecoder requested a review from Elson9 November 15, 2024 20:51
@ikethecoder ikethecoder merged commit 529c39d into dev Nov 18, 2024
6 of 7 checks passed
@ikethecoder ikethecoder deleted the feature/upstream-validator branch November 18, 2024 17:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Enforce validation on upstream service hosts for particular data planes
3 participants