blob: 8c842f15eededffbd2d27604033c5f88247334da [file] [log] [blame]
name: envoy.filters.http.rbac
typedConfig:
'@type': type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC
rules:
action: DENY
policies:
ns[foo]-policy[httpbin-deny]-rule[0]:
permissions:
- andRules:
rules:
- any: true
principals:
- andIds:
ids:
- orIds:
ids:
- authenticated:
principalName:
exact: spiffe://deny
shadowRulesStatPrefix: istio_dry_run_allow_