ipAllowPolicy with source: Remote and x-forwarded-for IP address does not work #6337
Labels
kind/bug
Categorizes issue or PR as related to a bug.
lifecycle/needs-triage
Indicates that an issue needs to be triaged by a project contributor.
lifecycle/stale
Denotes an issue or PR has remained open with no activity and has become stale.
What steps did you take and what happened:
We have httpproxy config with ipAllowPolicy:
What did you expect to happen:
The IP from range a.b.c.d/29 should be allowed but actually it is blocked with "RBAC: access denied" and "enforced denied, matched policy none" in envoy logs.
Anything else you would like to add:
Contour is configured with
num-trusted-hops: 1
.envoy config_dump
envoy debug logs:
Environment:
kubectl version
): 1.28.3/etc/os-release
): Ubuntu 22.04The text was updated successfully, but these errors were encountered: