Linkerd 인가 정책
Linkerd 인가 정책 (Authorization Policy)
Linkerd의 인가 정책은 메시된 파드에 어떤 유형의 트래픽이 허용되는지 제어할 수 있게 해 줘요. 이것이 무엇을 의미하는지에 대한 자세한 내용은 Authorization Policy 기능 설명을 참고하세요.
Linkerd의 정책은 두 가지 메커니즘으로 구성돼요:
- 기본 정책 집합. Kubernetes 어노테이션을 통해 클러스터, 네임스페이스, 워크로드 레벨에서 설정할 수 있어요.
- 특정 포트, 라우트, 워크로드 등에 대한 세밀한 정책을 지정하는 CRD 집합.
기본 정책 (Default policies)
Linkerd를 설치하는 동안 proxy.defaultInboundPolicy 필드로 클러스터 전체의 기본 정책을 지정해요. 이 필드는 다음 중 하나일 수 있어요:
- all-unauthenticated: 모든 트래픽을 허용. 기본값이에요.
- all-authenticated: 같은 클러스터 또는 (멀티 클러스터로) 다른 클러스터의 메시된 클라이언트의 트래픽을 허용.
- cluster-authenticated: 같은 클러스터의 메시된 클라이언트의 트래픽을 허용.
- cluster-unauthenticated: 같은 클러스터의 메시된 클라이언트와 메시되지 않은 클라이언트 모두의 트래픽을 허용.
- deny: 모든 트래픽을 거부.
- audit: all-unauthenticated와 같지만 요청이 로그와 메트릭에 플래그로 표시돼요.
이 클러스터 전체 기본값은 파드 스펙 또는 네임스페이스에 config.linkerd.io/default-inbound-policy 어노테이션을 설정해서 특정 리소스에 대해 재정의할 수 있어요.
동적 정책 리소스 (Dynamic policy resources)
정책을 동적으로 제어하고 기본 정책이 허용하는 것보다 더 세밀한 정책을 만들기 위해, Linkerd는 클러스터의 트래픽 정책을 제어하는 CRD 집합을 제공해요: Server, HTTPRoute, ServerAuthorization, AuthorizationPolicy, MeshTLSAuthentication, NetworkAuthentication.
인가의 일반적인 패턴은 다음과 같아요:
- Server는 파드 집합과 그 파드의 단일 포트를 설명해요.
- 선택적으로, HTTPRoute가 그 Server를 참조하고 그 Server로 가는 HTTP 트래픽의 부분집합을 설명해요.
- MeshTLSAuthentication 또는 NetworkAuthentication이 누가 접근을 허용받는지 설명해요.
- AuthorizationPolicy가 HTTPRoute 또는 Server(인가 대상)와 MeshTLSAuthentication 또는 NetworkAuthentication(인가를 가진 클라이언트)을 참조해요.
Server
Server는 서버와 같은 네임스페이스에 있는 파드 집합의 포트를 선택해요. 보통 파드의 단일 포트를 선택하지만, 포트를 이름으로 참조할 때(예: admin-http) 여러 포트를 선택할 수도 있어요. Server 리소스는 Kubernetes Service와 비슷하지만, 여러 Server 인스턴스가 겹치면 안 된다는 제약이 추가로 있어요. 즉, 같은 파드/포트 쌍을 선택하면 안 됩니다. Linkerd는 겹치는 Server가 생성되지 않도록 방지하는 admission controller를 포함하고 있어요.
참고
Server 리소스가 있으면 그 파드의 해당 포트로 가는 모든 트래픽은 명시적으로 인가되지 않거나(또는 accessPolicy:audit로 감사 모드가 활성화되지 않는 한) 거부돼요. 따라서 Server는 보통 그 Server를 참조하는 AuthorizationPolicy와 함께 짝을 이루거나, 그 Server를 다시 참조하는 HTTPRoute를 참조하는 AuthorizationPolicy와 함께 짝을 이뤄요.
Server 스펙
Server 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| accessPolicy | accessPolicy declares the policy applied to traffic not matching any associated authorization policies (defaults to deny). |
| podSelector | A podSelector selects pods in the same namespace. |
| port | A port name or number. Only ports in a pod spec's ports are considered. |
| proxyProtocol | Configures protocol discovery for inbound connections. Supersedes the config.linkerd.io/opaque-ports annotation. Must be one of unknown,HTTP/1,HTTP/2,gRPC,opaque,TLS. Defaults to unknown if not set. |
accessPolicy
Server와 연결된 인가 정책에 부합하지 않는 트래픽은 기본적으로 거부돼요. accessPolicy 필드를 재정의하면 이 동작을 바꿀 수 있어요. 이 필드는 기본 정책과 같은 값을 받아들여요. 특히 주목할 것은 audit 값인데, 이 값을 사용하면 정책을 강제 적용하기 전에 테스트할 수 있는 감사 모드가 활성화돼요.
podSelector
이것은 Kubernetes의 labelSelector 필드와 같아요. 이 셀렉터에 속하는 모든 파드는 Server 그룹에 포함돼요. podSelector 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| matchExpressions | matchExpressions is a list of label selector requirements. The requirements are ANDed. |
| matchLabels | matchLabels is a map of {key,value} pairs. |
자세한 내용은 Kubernetes LabelSelector 레퍼런스를 참고하세요.
Server 예시
특정 레이블이 있는 파드를 선택하고 proxyProtocol이 gRPC인 Server:
apiVersion: policy.linkerd.io/v1beta1
kind: Server
metadata:
namespace: emojivoto
name: emoji-grpc
spec:
podSelector:
matchLabels:
app: emoji-svc
port: grpc
proxyProtocol: gRPC
matchExpressions로 파드를 선택하고 proxyProtocol이 HTTP/2이며 포트가 8080인 Server:
apiVersion: policy.linkerd.io/v1beta1
kind: Server
metadata:
namespace: emojivoto
name: backend-services
spec:
podSelector:
matchExpressions:
- { key: app, operator: In, values: [voting-svc, emoji-svc] }
- { key: environment, operator: NotIn, values: [dev] }
port: 8080
proxyProtocol: "HTTP/2"
HTTPRoute
Server에 연결되면 HTTPRoute 리소스는 요청이 일치하는지 결정하는 규칙 집합을 선언함으로써 그 Server의 파드 포트가 처리하는 트래픽의 부분집합을 나타내요. 매칭은 경로, 헤더, 쿼리 파라미터 및/또는 동사(verb)에 기반할 수 있어요. AuthorizationPolicy는 HTTPRoute 리소스를 대상으로 할 수 있으므로, 전체 Server가 아니라 해당 HTTPRoute에만 트래픽을 인가할 수 있어요. HTTPRoute는 요청 또는 응답 수명주기 동안 완료되어야 하는 처리 단계를 추가하는 필터를 정의할 수도 있어요.
참고
주어진 HTTP 요청은 오직 하나의 HTTPRoute에만 일치할 수 있어요. 요청에 일치하는 HTTPRoute가 여러 개 있으면 Gateway API 규칙의 우선순위에 따라 하나가 선택돼요.
HTTPRoute의 전체 스펙을 참고하세요.
참고
HTTPRoute 리소스의 두 가지 버전을 Linkerd와 함께 사용할 수 있어요:
- Gateway API가 제공하는 업스트림 버전(
gateway.networking.k8s.ioAPI 그룹) - Linkerd가 제공하는 Linkerd 특화 CRD(
policy.linkerd.ioAPI 그룹)
두 HTTPRoute 리소스 정의는 비슷하지만, Linkerd 버전은 업스트림 Gateway API 리소스 정의에는 아직 없는 실험적 기능을 구현해요. 자세한 내용은 HTTPRoute 레퍼런스 문서를 참고하세요.
AuthorizationPolicy
AuthorizationPolicy는 Server 또는 HTTPRoute에 대한 트래픽을 인가하는 방법을 제공해요. AuthorizationPolicy는 ServerAuthorization의 대체물로, HTTPRoute를 대상으로 할 수 있기 때문에 Server만 대상으로 할 수 있는 ServerAuthorization보다 더 유연해요.
AuthorizationPolicy 스펙
AuthorizationPolicy 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| targetRef | A TargetRef which references a resource to which the authorization policy applies. |
| requiredAuthenticationRefs | A list of TargetRefs representing the required authentications. In the case of multiple entries, all authentications must match. |
targetRef
TargetRef는 이 AuthorizationPolicy가 적용되는 API 객체를 식별해요. 지원되는 API 객체는:
- Server - AuthorizationPolicy가 그 Server로 가는 모든 트래픽에 적용됨을 나타내요.
- HTTPRoute - AuthorizationPolicy가 그 HTTPRoute와 일치하는 모든 트래픽에 적용됨을 나타내요.
- namespace(kind: Namespace) - AuthorizationPolicy가 그 네임스페이스에 정의된 모든 Server와 HTTPRoute로 가는 모든 트래픽에 적용됨을 나타내요. 이는 AuthorizationPolicy 자신의 네임스페이스만 가능해요.
| field | value |
|---|---|
| group | Group is the group of the target resource. For namespace kinds, this should be omitted. |
| kind | Kind is kind of the target resource. |
| name | Name is the name of the target resource. |
AuthorizationPolicy 예시
authors-get-authn 인증을 충족하는 클라이언트가 authors-get-route HTTPRoute로 보낼 수 있게 인가하는 AuthorizationPolicy:
apiVersion: policy.linkerd.io/v1alpha1
kind: AuthorizationPolicy
metadata:
name: authors-get-policy
namespace: booksapp
spec:
targetRef:
group: policy.linkerd.io
kind: HTTPRoute
name: authors-get-route
requiredAuthenticationRefs:
- name: authors-get-authn
kind: MeshTLSAuthentication
group: policy.linkerd.io
webapp ServiceAccount가 authors Server로 보낼 수 있게 인가하는 AuthorizationPolicy:
apiVersion: policy.linkerd.io/v1alpha1
kind: AuthorizationPolicy
metadata:
name: authors-policy
namespace: booksapp
spec:
targetRef:
group: policy.linkerd.io
kind: Server
name: authors
requiredAuthenticationRefs:
- name: webapp
kind: ServiceAccount
webapp ServiceAccount가 booksapp 네임스페이스 안의 모든 정책 '대상(target)'으로 보낼 수 있게 인가하는 AuthorizationPolicy:
apiVersion: policy.linkerd.io/v1alpha1
kind: AuthorizationPolicy
metadata:
name: authors-policy
namespace: booksapp
spec:
targetRef:
kind: Namespace
name: booksapp
requiredAuthenticationRefs:
- name: webapp
kind: ServiceAccount
MeshTLSAuthentication
MeshTLSAuthentication은 메시 아이덴티티의 집합을 나타내요. AuthorizationPolicy가 requiredAuthenticationRefs 중 하나로 MeshTLSAuthentication을 가지면, 클라이언트가 메시 안에 있어야 하고 지정된 아이덴티티 중 하나를 가져야만 대상으로 보낼 수 있게 인가된다는 뜻이에요.
MeshTLSAuthentication 스펙
MeshTLSAuthentication 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| identities | A list of mTLS identities to authenticate. The * prefix can be used to match all identities in a domain. An identity string of * indicates that all meshed clients are authorized. |
| identityRefs | A list of targetRefs to ServiceAccounts to authenticate. |
MeshTLSAuthentication 예시
books와 webapp 메시 아이덴티티를 인증하는 MeshTLSAuthentication:
apiVersion: policy.linkerd.io/v1alpha1
kind: MeshTLSAuthentication
metadata:
name: authors-get-authn
namespace: booksapp
spec:
identities:
- "books.booksapp.serviceaccount.identity.linkerd.cluster.local"
- "webapp.booksapp.serviceaccount.identity.linkerd.cluster.local"
books와 webapp 메시 아이덴티티를 인증하는 MeshTLSAuthentication. 위 예시와 동일한 것을 지정하는 대안적 방법이에요:
apiVersion: policy.linkerd.io/v1alpha1
kind: MeshTLSAuthentication
metadata:
name: authors-get-authn
namespace: booksapp
spec:
identityRefs:
- kind: ServiceAccount
name: books
- kind: ServiceAccount
name: webapp
모든 메시 아이덴티티를 인증하는 MeshTLSAuthentication:
apiVersion: policy.linkerd.io/v1alpha1
kind: MeshTLSAuthentication
metadata:
name: authors-get-authn
namespace: booksapp
spec:
identities: ["*"]
NetworkAuthentication
NetworkAuthentication은 IP 서브넷의 집합을 나타내요. AuthorizationPolicy가 requiredAuthenticationRefs 중 하나로 NetworkAuthentication을 가지면, 클라이언트가 지정된 네트워크 중 하나에 있어야만 대상으로 보낼 수 있게 인가된다는 뜻이에요.
NetworkAuthentication 스펙
NetworkAuthentication 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| networks | A list of networks to authenticate. |
network
network는 인증된 IP 서브넷을 정의해요.
| field | value |
|---|---|
| cidr | A subnet in CIDR notation to authenticate. |
| except | A list of subnets in CIDR notation to exclude from the authentication. |
NetworkAuthentication 예시
지정된 CIDR 중 하나에 속하는 클라이언트를 인증하는 NetworkAuthentication:
apiVersion: policy.linkerd.io/v1alpha1
kind: NetworkAuthentication
metadata:
name: cluster-network
namespace: booksapp
spec:
networks:
- cidr: 10.0.0.0/8
- cidr: 100.64.0.0/10
- cidr: 172.16.0.0/12
- cidr: 192.168.0.0/16
ServerAuthorization
ServerAuthorization은 하나 이상의 Server에 대한 트래픽을 인가하는 방법을 제공해요.
참고
AuthorizationPolicy는 ServerAuthorization보다 더 유연한 대안으로, Server뿐만 아니라 HTTPRoute도 대상으로 할 수 있어요. AuthorizationPolicy 사용이 권장되며, ServerAuthorization는 향후 릴리스에서 deprecated 될 예정이에요.
ServerAuthorization 스펙
ServerAuthorization 스펙은 다음 최상위 필드를 포함해야 해요:
| field | value |
|---|---|
| client | A client describes clients authorized to access a server. |
| server | A serverRef identifies Servers in the same namespace for which this authorization applies. |
serverRef
serverRef 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| name | References a Server instance by name. |
| selector | A selector selects servers on which this authorization applies in the same namespace. |
selector
이것은 Kubernetes의 labelSelector 필드와 같아요. 이 셀렉터에 속하는 모든 서버에 이 인가가 적용돼요. selector 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| matchExpressions | A list of label selector requirements. The requirements are ANDed. |
| matchLabels | A map of {key,value} pairs. |
자세한 내용은 Kubernetes LabelSelector 레퍼런스를 참고하세요.
client
client 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| meshTLS | A meshTLS is used to authorize meshed clients to access a server. |
| unauthenticated | A boolean value that authorizes unauthenticated clients to access a server. |
선택적으로 networks 필드도 포함할 수 있어요:
| field | value |
|---|---|
| networks | Limits the client IP addresses to which this authorization applies. If unset, the server chooses a default (typically, all IPs or the cluster's pod network). |
meshTLS
meshTLS 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| unauthenticatedTLS | A boolean to indicate that no client identity is required for communication. This is mostly important for the identity controller, which must terminate TLS connections from clients that do not yet have a certificate. |
| identities | A list of proxy identity strings (as provided via mTLS) that are authorized. The * prefix can be used to match all identities in a domain. An identity string of * indicates that all authentication clients are authorized. |
| serviceAccounts | A list of authorized client serviceAccounts (as provided via mTLS). |
serviceAccount
serviceAccount 필드는 다음 최상위 필드를 포함해요:
| field | value |
|---|---|
| name | The ServiceAccount's name. |
| namespace | The ServiceAccount's namespace. If unset, the authorization's namespace is used. |
ServerAuthorization 예시
*.emojivoto.serviceaccount.identity.linkerd.cluster.local 프록시 아이덴티티, 즉 emojivoto 네임스페이스의 모든 서비스 어카운트를 가진 메시된 클라이언트를 허용하는 ServerAuthorization:
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
namespace: emojivoto
name: emoji-grpc
spec:
# Allow all authenticated clients to access the (read-only) emoji service.
server:
selector:
matchLabels:
app: emoji-svc
client:
meshTLS:
identities:
- "*.emojivoto.serviceaccount.identity.linkerd.cluster.local"
인증되지 않은 클라이언트를 허용하는 ServerAuthorization:
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
namespace: emojivoto
name: web-public
spec:
server:
name: web-http
# Allow all clients to access the web HTTP port without regard for
# authentication. If unauthenticated connections are permitted, there is no
# need to describe authenticated clients.
client:
unauthenticated: true
networks:
- cidr: 0.0.0.0/0
- cidr: ::/0
특정 서비스 어카운트를 가진 메시된 클라이언트를 허용하는 ServerAuthorization:
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
namespace: emojivoto
name: prom-prometheus
spec:
server:
name: prom
client:
meshTLS:
serviceAccounts:
- namespace: linkerd-viz
name: prometheus
본문
Linkerd의 인가 정책은 메시된 파드에 어떤 유형의 트래픽이 허용되는지 제어할 수 있게 해 줘요. 이것이 무엇을 의미하는지에 대한 자세한 내용은 Authorization Policy 기능 설명을 참고하세요.
Linkerd의 정책은 두 가지 메커니즘으로 구성돼요:
- 기본 정책 집합. Kubernetes 어노테이션을 통해 클러스터, 네임스페이스, 워크로드 레벨에서 설정할 수 있어요.
- 특정 포트, 라우트, 워크로드 등에 대한 세밀한 정책을 지정하는 CRD 집합.
기본 정책 (Default policies)
Linkerd를 설치하는 동안 proxy.defaultInboundPolicy 필드로 클러스터 전체의 기본 정책을 지정해요. 이 필드는 다음 중 하나일 수 있어요:
- all-unauthenticated: 모든 트래픽을 허용. 기본값이에요.
- all-authenticated: 같은 클러스터 또는 (멀티 클러스터로) 다른 클러스터의 메시된 클라이언트의 트래픽을 허용.
- cluster-authenticated: 같은 클러스터의 메시된 클라이언트의 트래픽을 허용.
- cluster-unauthenticated: 같은 클러스터의 메시된 클라이언트와 메시되지 않은 클라이언트 모두의 트래픽을 허용.
- deny: 모든 트래픽을 거부.
- audit: all-unauthenticated와 같지만 요청이 로그와 메트릭에 플래그로 표시돼요.
이 클러스터 전체 기본값은 파드 스펙 또는 네임스페이스에 config.linkerd.io/default-inbound-policy 어노테이션을 설정해서 특정 리소스에 대해 재정의할 수 있어요.
동적 정책 리소스 (Dynamic policy resources)
정책을 동적으로 제어하고 기본 정책이 허용하는 것보다 더 세밀한 정책을 만들기 위해, Linkerd는 클러스터의 트래픽 정책을 제어하는 CRD 집합을 제공해요: Server, HTTPRoute, ServerAuthorization, AuthorizationPolicy, MeshTLSAuthentication, NetworkAuthentication.
인가의 일반적인 패턴은 다음과 같아요:
- Server는 파드 집합과 그 파드의 단일 포트를 설명해요.
- 선택적으로, HTTPRoute가 그 Server를 참조하고 그 Server로 가는 HTTP 트래픽의 부분집합을 설명해요.
- MeshTLSAuthentication 또는 NetworkAuthentication이 누가 접근을 허용받는지 설명해요.
- AuthorizationPolicy가 HTTPRoute 또는 Server(인가 대상)와 MeshTLSAuthentication 또는 NetworkAuthentication(인가를 가진 클라이언트)을 참조해요.
Server
Server는 서버와 같은 네임스페이스에 있는 파드 집합의 포트를 선택해요. 보통 파드의 단일 포트를 선택하지만, 포트를 이름으로 참조할 때(예: admin-http) 여러 포트를 선택할 수도 있어요. Server 리소스는 Kubernetes Service와 비슷하지만, 여러 Server 인스턴스가 겹치면 안 된다는 제약이 추가로 있어요. 즉, 같은 파드/포트 쌍을 선택하면 안 됩니다. Linkerd는 겹치는 Server가 생성되지 않도록 방지하는 admission controller를 포함하고 있어요.
참고
Server 리소스가 있으면 그 파드의 해당 포트로 가는 모든 트래픽은 명시적으로 인가되지 않거나(또는 accessPolicy:audit로 감사 모드가 활성화되지 않는 한) 거부돼요. 따라서 Server는 보통 그 Server를 참조하는 AuthorizationPolicy와 함께 짝을 이루거나, 그 Server를 다시 참조하는 HTTPRoute를 참조하는 AuthorizationPolicy와 함께 짝을 이뤄요.
Server 스펙
Server 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| accessPolicy | accessPolicy declares the policy applied to traffic not matching any associated authorization policies (defaults to deny). |
| podSelector | A podSelector selects pods in the same namespace. |
| port | A port name or number. Only ports in a pod spec's ports are considered. |
| proxyProtocol | Configures protocol discovery for inbound connections. Supersedes the config.linkerd.io/opaque-ports annotation. Must be one of unknown,HTTP/1,HTTP/2,gRPC,opaque,TLS. Defaults to unknown if not set. |
accessPolicy
Server와 연결된 인가 정책에 부합하지 않는 트래픽은 기본적으로 거부돼요. accessPolicy 필드를 재정의하면 이 동작을 바꿀 수 있어요. 이 필드는 기본 정책과 같은 값을 받아들여요. 특히 주목할 것은 audit 값인데, 이 값을 사용하면 정책을 강제 적용하기 전에 테스트할 수 있는 감사 모드가 활성화돼요.
podSelector
이것은 Kubernetes의 labelSelector 필드와 같아요. 이 셀렉터에 속하는 모든 파드는 Server 그룹에 포함돼요. podSelector 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| matchExpressions | matchExpressions is a list of label selector requirements. The requirements are ANDed. |
| matchLabels | matchLabels is a map of {key,value} pairs. |
자세한 내용은 Kubernetes LabelSelector 레퍼런스를 참고하세요.
Server 예시
특정 레이블이 있는 파드를 선택하고 proxyProtocol이 gRPC인 Server:
apiVersion: policy.linkerd.io/v1beta1
kind: Server
metadata:
namespace: emojivoto
name: emoji-grpc
spec:
podSelector:
matchLabels:
app: emoji-svc
port: grpc
proxyProtocol: gRPC
matchExpressions로 파드를 선택하고 proxyProtocol이 HTTP/2이며 포트가 8080인 Server:
apiVersion: policy.linkerd.io/v1beta1
kind: Server
metadata:
namespace: emojivoto
name: backend-services
spec:
podSelector:
matchExpressions:
- { key: app, operator: In, values: [voting-svc, emoji-svc] }
- { key: environment, operator: NotIn, values: [dev] }
port: 8080
proxyProtocol: "HTTP/2"
HTTPRoute
Server에 연결되면 HTTPRoute 리소스는 요청이 일치하는지 결정하는 규칙 집합을 선언함으로써 그 Server의 파드 포트가 처리하는 트래픽의 부분집합을 나타내요. 매칭은 경로, 헤더, 쿼리 파라미터 및/또는 동사(verb)에 기반할 수 있어요. AuthorizationPolicy는 HTTPRoute 리소스를 대상으로 할 수 있으므로, 전체 Server가 아니라 해당 HTTPRoute에만 트래픽을 인가할 수 있어요. HTTPRoute는 요청 또는 응답 수명주기 동안 완료되어야 하는 처리 단계를 추가하는 필터를 정의할 수도 있어요.
참고
주어진 HTTP 요청은 오직 하나의 HTTPRoute에만 일치할 수 있어요. 요청에 일치하는 HTTPRoute가 여러 개 있으면 Gateway API 규칙의 우선순위에 따라 하나가 선택돼요.
HTTPRoute의 전체 스펙을 참고하세요.
참고
HTTPRoute 리소스의 두 가지 버전을 Linkerd와 함께 사용할 수 있어요:
- Gateway API가 제공하는 업스트림 버전(
gateway.networking.k8s.ioAPI 그룹) - Linkerd가 제공하는 Linkerd 특화 CRD(
policy.linkerd.ioAPI 그룹)
두 HTTPRoute 리소스 정의는 비슷하지만, Linkerd 버전은 업스트림 Gateway API 리소스 정의에는 아직 없는 실험적 기능을 구현해요. 자세한 내용은 HTTPRoute 레퍼런스 문서를 참고하세요.
AuthorizationPolicy
AuthorizationPolicy는 Server 또는 HTTPRoute에 대한 트래픽을 인가하는 방법을 제공해요. AuthorizationPolicy는 ServerAuthorization의 대체물로, HTTPRoute를 대상으로 할 수 있기 때문에 Server만 대상으로 할 수 있는 ServerAuthorization보다 더 유연해요.
AuthorizationPolicy 스펙
AuthorizationPolicy 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| targetRef | A TargetRef which references a resource to which the authorization policy applies. |
| requiredAuthenticationRefs | A list of TargetRefs representing the required authentications. In the case of multiple entries, all authentications must match. |
targetRef
TargetRef는 이 AuthorizationPolicy가 적용되는 API 객체를 식별해요. 지원되는 API 객체는:
- Server - AuthorizationPolicy가 그 Server로 가는 모든 트래픽에 적용됨을 나타내요.
- HTTPRoute - AuthorizationPolicy가 그 HTTPRoute와 일치하는 모든 트래픽에 적용됨을 나타내요.
- namespace(kind: Namespace) - AuthorizationPolicy가 그 네임스페이스에 정의된 모든 Server와 HTTPRoute로 가는 모든 트래픽에 적용됨을 나타내요. 이는 AuthorizationPolicy 자신의 네임스페이스만 가능해요.
| field | value |
|---|---|
| group | Group is the group of the target resource. For namespace kinds, this should be omitted. |
| kind | Kind is kind of the target resource. |
| name | Name is the name of the target resource. |
AuthorizationPolicy 예시
authors-get-authn 인증을 충족하는 클라이언트가 authors-get-route HTTPRoute로 보낼 수 있게 인가하는 AuthorizationPolicy:
apiVersion: policy.linkerd.io/v1alpha1
kind: AuthorizationPolicy
metadata:
name: authors-get-policy
namespace: booksapp
spec:
targetRef:
group: policy.linkerd.io
kind: HTTPRoute
name: authors-get-route
requiredAuthenticationRefs:
- name: authors-get-authn
kind: MeshTLSAuthentication
group: policy.linkerd.io
webapp ServiceAccount가 authors Server로 보낼 수 있게 인가하는 AuthorizationPolicy:
apiVersion: policy.linkerd.io/v1alpha1
kind: AuthorizationPolicy
metadata:
name: authors-policy
namespace: booksapp
spec:
targetRef:
group: policy.linkerd.io
kind: Server
name: authors
requiredAuthenticationRefs:
- name: webapp
kind: ServiceAccount
webapp ServiceAccount가 booksapp 네임스페이스 안의 모든 정책 '대상(target)'으로 보낼 수 있게 인가하는 AuthorizationPolicy:
apiVersion: policy.linkerd.io/v1alpha1
kind: AuthorizationPolicy
metadata:
name: authors-policy
namespace: booksapp
spec:
targetRef:
kind: Namespace
name: booksapp
requiredAuthenticationRefs:
- name: webapp
kind: ServiceAccount
MeshTLSAuthentication
MeshTLSAuthentication은 메시 아이덴티티의 집합을 나타내요. AuthorizationPolicy가 requiredAuthenticationRefs 중 하나로 MeshTLSAuthentication을 가지면, 클라이언트가 메시 안에 있어야 하고 지정된 아이덴티티 중 하나를 가져야만 대상으로 보낼 수 있게 인가된다는 뜻이에요.
MeshTLSAuthentication 스펙
MeshTLSAuthentication 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| identities | A list of mTLS identities to authenticate. The * prefix can be used to match all identities in a domain. An identity string of * indicates that all meshed clients are authorized. |
| identityRefs | A list of targetRefs to ServiceAccounts to authenticate. |
MeshTLSAuthentication 예시
books와 webapp 메시 아이덴티티를 인증하는 MeshTLSAuthentication:
apiVersion: policy.linkerd.io/v1alpha1
kind: MeshTLSAuthentication
metadata:
name: authors-get-authn
namespace: booksapp
spec:
identities:
- "books.booksapp.serviceaccount.identity.linkerd.cluster.local"
- "webapp.booksapp.serviceaccount.identity.linkerd.cluster.local"
books와 webapp 메시 아이덴티티를 인증하는 MeshTLSAuthentication. 위 예시와 동일한 것을 지정하는 대안적 방법이에요:
apiVersion: policy.linkerd.io/v1alpha1
kind: MeshTLSAuthentication
metadata:
name: authors-get-authn
namespace: booksapp
spec:
identityRefs:
- kind: ServiceAccount
name: books
- kind: ServiceAccount
name: webapp
모든 메시 아이덴티티를 인증하는 MeshTLSAuthentication:
apiVersion: policy.linkerd.io/v1alpha1
kind: MeshTLSAuthentication
metadata:
name: authors-get-authn
namespace: booksapp
spec:
identities: ["*"]
NetworkAuthentication
NetworkAuthentication은 IP 서브넷의 집합을 나타내요. AuthorizationPolicy가 requiredAuthenticationRefs 중 하나로 NetworkAuthentication을 가지면, 클라이언트가 지정된 네트워크 중 하나에 있어야만 대상으로 보낼 수 있게 인가된다는 뜻이에요.
NetworkAuthentication 스펙
NetworkAuthentication 스펙은 다음 최상위 필드를 포함할 수 있어요:
| field | value |
|---|---|
| networks | A list of networks to authenticate. |
network
network는 인증된 IP 서브넷을 정의해요.
| field | value |
|---|---|
| cidr | A subnet in CIDR notation to authenticate. |
| except | A list of subnets in CIDR notation to exclude from the authentication. |
NetworkAuthentication 예시
지정된 CIDR 중 하나에 속하는 클라이언트를 인증하는 NetworkAuthentication:
apiVersion: policy.linkerd.io/v1alpha1
kind: NetworkAuthentication
metadata:
name: cluster-network
namespace: booksapp
spec:
networks:
- cidr: 10.0.0.0/8
- cidr: 100.64.0.0/10
- cidr: 172.16.0.0/12
- cidr: 192.168.0.0/16
ServerAuthorization
ServerAuthorization은 하나 이상의 Server에 대한 트래픽을 인가하는 방법을 제공해요.
참고
AuthorizationPolicy는 ServerAuthorization보다 더 유연한 대안으로, Server뿐만 아니라 HTTPRoute도 대상으로 할 수 있어요. AuthorizationPolicy 사용이 권장되며, ServerAuthorization는 향후 릴리스에서 deprecated 될 예정이에요.
ServerAuthorization 스펙
ServerAuthorization 스펙은 다음 최상위 필드를 포함해야 해요:
| field | value |
|---|---|
| client | A client describes clients authorized to access a server. |
| server | A serverRef identifies Servers in the same namespace for which this authorization applies. |
serverRef
serverRef 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| name | References a Server instance by name. |
| selector | A selector selects servers on which this authorization applies in the same namespace. |
selector
이것은 Kubernetes의 labelSelector 필드와 같아요. 이 셀렉터에 속하는 모든 서버에 이 인가가 적용돼요. selector 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| matchExpressions | A list of label selector requirements. The requirements are ANDed. |
| matchLabels | A map of {key,value} pairs. |
자세한 내용은 Kubernetes LabelSelector 레퍼런스를 참고하세요.
client
client 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| meshTLS | A meshTLS is used to authorize meshed clients to access a server. |
| unauthenticated | A boolean value that authorizes unauthenticated clients to access a server. |
선택적으로 networks 필드도 포함할 수 있어요:
| field | value |
|---|---|
| networks | Limits the client IP addresses to which this authorization applies. If unset, the server chooses a default (typically, all IPs or the cluster's pod network). |
meshTLS
meshTLS 객체는 다음 필드 중 정확히 하나를 포함해야 해요:
| field | value |
|---|---|
| unauthenticatedTLS | A boolean to indicate that no client identity is required for communication. This is mostly important for the identity controller, which must terminate TLS connections from clients that do not yet have a certificate. |
| identities | A list of proxy identity strings (as provided via mTLS) that are authorized. The * prefix can be used to match all identities in a domain. An identity string of * indicates that all authentication clients are authorized. |
| serviceAccounts | A list of authorized client serviceAccounts (as provided via mTLS). |
serviceAccount
serviceAccount 필드는 다음 최상위 필드를 포함해요:
| field | value |
|---|---|
| name | The ServiceAccount's name. |
| namespace | The ServiceAccount's namespace. If unset, the authorization's namespace is used. |
ServerAuthorization 예시
*.emojivoto.serviceaccount.identity.linkerd.cluster.local 프록시 아이덴티티, 즉 emojivoto 네임스페이스의 모든 서비스 어카운트를 가진 메시된 클라이언트를 허용하는 ServerAuthorization:
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
namespace: emojivoto
name: emoji-grpc
spec:
# Allow all authenticated clients to access the (read-only) emoji service.
server:
selector:
matchLabels:
app: emoji-svc
client:
meshTLS:
identities:
- "*.emojivoto.serviceaccount.identity.linkerd.cluster.local"
인증되지 않은 클라이언트를 허용하는 ServerAuthorization:
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
namespace: emojivoto
name: web-public
spec:
server:
name: web-http
# Allow all clients to access the web HTTP port without regard for
# authentication. If unauthenticated connections are permitted, there is no
# need to describe authenticated clients.
client:
unauthenticated: true
networks:
- cidr: 0.0.0.0/0
- cidr: ::/0
특정 서비스 어카운트를 가진 메시된 클라이언트를 허용하는 ServerAuthorization:
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
namespace: emojivoto
name: prom-prometheus
spec:
server:
name: prom
client:
meshTLS:
serviceAccounts:
- namespace: linkerd-viz
name: prometheus