blob: ca9eb669003c5de472fe760751a8b9a6a856387a [file] [log] [blame]
name: envoy.filters.network.rbac
typedConfig:
'@type': type.googleapis.com/envoy.extensions.filters.network.rbac.v3.RBAC
rules:
policies:
ns[foo]-policy[httpbin-2]-rule[0]:
permissions:
- andRules:
rules:
- orRules:
rules:
- destinationPort: 9000
principals:
- andIds:
ids:
- any: true
shadowRules:
policies:
ns[foo]-policy[httpbin-1]-rule[0]:
permissions:
- andRules:
rules:
- orRules:
rules:
- destinationPort: 80
principals:
- andIds:
ids:
- any: true
shadowRulesStatPrefix: istio_dry_run_allow_
statPrefix: tcp.