Skip to content

AuthPolicy compat: source.* attribute mapping #157

Description

@maleck13

Parent: #130

Map Kuadrant source.* (downstream client network + mesh identity) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Source attributes".

Approach: alias source.principal to caller_workload.spiffe_id once the host populates WorkloadIdentity from peer_identity; bridge client IP via custom.*; mesh fields have no PPE equivalent.

Acceptance (tiered testing — doc "Testing strategy"):

  • source.principal resolves to the SPIFFE id when peer identity is populated.
  • Tier 1: Authorino reference JSON + expected decision checked in for every source.* attribute, Gap rows (port, service, labels, certificate) recorded as expected divergence.
  • Tier 2: ppe-pdp-diff cases cover the SPIFFE-vs-raw-principal model difference and the missing-data fail-open case for unmapped source.*.
  • Tier 3: dual-gateway check for peer-identity / client-address surface only a live gateway exercises.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions