Fix proxy protocol support for Kube access flow (#29268)

This PR allows enabling/disabling the support for proxy protocol in Kubernetes access flow.
This commit is contained in:
Tiago Silva
2023-07-18 19:16:42 +00:00
committed by GitHub
parent 7b49931edb
commit 8c433e539c
2 changed files with 4 additions and 1 deletions
+3 -1
View File
@@ -96,6 +96,8 @@ type TLSServerConfig struct {
// kubernetes_service. The servers are kept in memory to avoid making unnecessary
// unmarshal calls followed by filtering and to improve memory usage.
KubernetesServersWatcher *services.KubeServerWatcher
// EnableProxyProtocol enables proxy protocol support
EnableProxyProtocol bool
}
// CheckAndSetDefaults checks and sets default values
@@ -272,7 +274,7 @@ func (t *TLSServer) Serve(listener net.Listener) error {
Context: t.Context,
Listener: listener,
Clock: t.Clock,
EnableExternalProxyProtocol: true,
EnableExternalProxyProtocol: t.EnableProxyProtocol,
ID: t.Component,
CertAuthorityGetter: caGetter,
LocalClusterName: t.ClusterName,
+1
View File
@@ -4215,6 +4215,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error {
Log: log,
IngressReporter: ingressReporter,
KubernetesServersWatcher: kubeServerWatcher,
EnableProxyProtocol: cfg.Proxy.EnableProxyProtocol,
})
if err != nil {
return trace.Wrap(err)