Skip to content

AuthPolicy compat: connection.* attribute mapping #159

Description

@maleck13

Parent: #130

Map Kuadrant connection.* (downstream TLS/mTLS state) onto PPE. Full attribute-by-attribute analysis: 00133 mapping doc (PR #131), section "Connection attributes".

Approach: alias connection.mtls to caller_workload.attestor == "mtls" (a verified client certificate — not plain server-auth TLS); raw TLS state only bridgeable if the host injects it; certificates/digests have no PPE equivalent.

Acceptance (tiered testing — doc "Testing strategy"):

  • connection.mtls resolves via attestor == "mtls", not conflated with plain TLS.
  • Tier 1: Authorino reference JSON + expected decision checked in for every connection.* attribute, Gap rows (SNI, tls_version, *_certificate, digest) recorded as expected divergence.
  • Tier 2: ppe-pdp-diff cases cover the boolean-vs-attestor-string model and the missing-data fail-open case for unmapped TLS fields.
  • Tier 3: dual-gateway check — mTLS is only truly exercised by a real TLS handshake, so this namespace has genuine tier-3 surface.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions