From 8c433e539c971abb7a24ea298477332db6ea70be Mon Sep 17 00:00:00 2001 From: Tiago Silva Date: Tue, 18 Jul 2023 20:16:42 +0100 Subject: [PATCH] Fix proxy protocol support for Kube access flow (#29268) This PR allows enabling/disabling the support for proxy protocol in Kubernetes access flow. --- lib/kube/proxy/server.go | 4 +++- lib/service/service.go | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/lib/kube/proxy/server.go b/lib/kube/proxy/server.go index 064058b4d1f..a3493d1f0fa 100644 --- a/lib/kube/proxy/server.go +++ b/lib/kube/proxy/server.go @@ -96,6 +96,8 @@ type TLSServerConfig struct { // kubernetes_service. The servers are kept in memory to avoid making unnecessary // unmarshal calls followed by filtering and to improve memory usage. KubernetesServersWatcher *services.KubeServerWatcher + // EnableProxyProtocol enables proxy protocol support + EnableProxyProtocol bool } // CheckAndSetDefaults checks and sets default values @@ -272,7 +274,7 @@ func (t *TLSServer) Serve(listener net.Listener) error { Context: t.Context, Listener: listener, Clock: t.Clock, - EnableExternalProxyProtocol: true, + EnableExternalProxyProtocol: t.EnableProxyProtocol, ID: t.Component, CertAuthorityGetter: caGetter, LocalClusterName: t.ClusterName, diff --git a/lib/service/service.go b/lib/service/service.go index 70dba3a7264..943c7e1d2a3 100644 --- a/lib/service/service.go +++ b/lib/service/service.go @@ -4215,6 +4215,7 @@ func (process *TeleportProcess) initProxyEndpoint(conn *Connector) error { Log: log, IngressReporter: ingressReporter, KubernetesServersWatcher: kubeServerWatcher, + EnableProxyProtocol: cfg.Proxy.EnableProxyProtocol, }) if err != nil { return trace.Wrap(err)