Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(meshpassthrough): disable tls and http inspector for mysql protocol #12839

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

lukidzi
Copy link
Contributor

@lukidzi lukidzi commented Feb 12, 2025

Motivation

When trying to communicate with MySQL, the user wants to enable communication with the database. Unfortunately, the MySQL protocol is slightly different, and the usual method of configuring filter chains does not work when using MeshPassthrough.

Implementation information

  • Added original_dst listener filter
  • Added a protocol mysql which works only with CIDR/IP and requires port since we need to disable tls_inspector and http_inspector listener filters for the port
  • Mysql protocol creates a tcp_proxy but with with disabled listener filters
  • Added test

Why added mysql protocol and not just disable on ports with TCP protocol?

The user may have rules with HTTP traffic and TCP traffic on the same port matching different IP. example: tls matching on port 8080(IP: 192.168.1.1) and TCP matching on 8080 (IP: 172.1.1.1), that would disable TLS inspector on the port 8080 and wouldn't match

Supporting documentation

https://dev.mysql.com/doc/dev/mysql-server/8.4.3/page_protocol_connection_phase_packets.html
envoyproxy/envoy#21044

@lukidzi lukidzi requested a review from a team as a code owner February 12, 2025 16:40
Copy link
Contributor

Reviewer Checklist

🔍 Each of these sections need to be checked by the reviewer of the PR 🔍:
If something doesn't apply please check the box and add a justification if the reason is non obvious.

  • Is the PR title satisfactory? Is this part of a larger feature and should be grouped using > Changelog?
  • PR description is clear and complete. It Links to relevant issue as well as docs and UI issues
  • This will not break child repos: it doesn't hardcode values (.e.g "kumahq" as an image registry)
  • IPv6 is taken into account (.e.g: no string concatenation of host port)
  • Tests (Unit test, E2E tests, manual test on universal and k8s)
    • Don't forget ci/ labels to run additional/fewer tests
  • Does this contain a change that needs to be notified to users? In this case, UPGRADE.md should be updated.
  • Does it need to be backported according to the backporting policy? (this GH action will add "backport" label based on these file globs, if you want to prevent it from adding the "backport" label use no-backport-autolabel label)

Signed-off-by: Lukasz Dziedziak <[email protected]>
@lukidzi lukidzi added this to the 2.10.x milestone Feb 12, 2025
@lukidzi lukidzi changed the title fix(meshpassthrough): communicate with mysql fix(meshpassthrough): disable tls and http inspector for TCP protocol Feb 12, 2025
@lukidzi lukidzi changed the title fix(meshpassthrough): disable tls and http inspector for TCP protocol fix(meshpassthrough): disable tls and http inspector for mysql protocol Feb 12, 2025
@jijiechen jijiechen self-requested a review February 13, 2025 03:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant