| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994 |
- resources:
- - '@type': type.googleapis.com/envoy.config.listener.v3.Listener
- name: briven
- per_connection_buffer_limit_bytes: 32768 # 32 KiB
-
- address:
- socket_address:
- address: 0.0.0.0
- port_value: 8000
-
- filter_chains:
- - filters:
- - name: envoy.filters.network.http_connection_manager
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
- stat_prefix: ingress_http
- normalize_path: true
- merge_slashes: true
- path_with_escaped_slashes_action: REJECT_REQUEST
- use_remote_address: true
- common_http_protocol_options:
- headers_with_underscores_action: REJECT_REQUEST
- upgrade_configs:
- - upgrade_type: websocket
- access_log:
- - name: envoy.access_loggers.stdout
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
- log_format:
- text_format_source:
- inline_string: "%DOWNSTREAM_REMOTE_ADDRESS_WITHOUT_PORT% - - [%START_TIME(%d/%b/%Y:%H:%M:%S %z)%] \"%REQ(:METHOD)% %REQ(X-ENVOY-ORIGINAL-PATH?:PATH)% %PROTOCOL%\" %RESPONSE_CODE% %BYTES_SENT% \"%REQ(REFERER)%\" \"%REQ(USER-AGENT)%\"\n"
-
- route_config:
- name: briven_route
- virtual_hosts:
- - name: briven_host
- domains:
- - '*'
- cors:
- allow_origin_string_match:
- - safe_regex:
- regex: ".*"
- allow_methods: "GET,POST,PUT,PATCH,DELETE,OPTIONS,HEAD,CONNECT,TRACE"
- allow_headers: "*"
- expose_headers: "*"
- max_age: "3600"
- request_headers_to_add:
- - header:
- key: X-Forwarded-Host
- value: "%REQ(:AUTHORITY)%"
- append_action: ADD_IF_ABSENT
- - header:
- key: X-Forwarded-Port
- value: "%DOWNSTREAM_LOCAL_PORT%"
- append_action: ADD_IF_ABSENT
- routes:
- - match:
- prefix: /auth/v1/verify
- route:
- cluster: auth
- prefix_rewrite: /verify
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /auth/v1/verify
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
-
- - match:
- prefix: /auth/v1/callback
- route:
- cluster: auth
- prefix_rewrite: /callback
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /auth/v1/callback
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
-
- - match:
- prefix: /auth/v1/authorize
- route:
- cluster: auth
- prefix_rewrite: /authorize
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /auth/v1/authorize
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
- - match:
- prefix: /auth/v1/.well-known/jwks.json
- route:
- cluster: auth
- prefix_rewrite: /.well-known/jwks.json
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /auth/v1/.well-known/jwks.json
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
- - match:
- prefix: /.well-known/oauth-authorization-server
- route:
- cluster: auth
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /.well-known/oauth-authorization-server
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
- - match:
- prefix: /sso/saml/acs
- route:
- cluster: auth
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /sso/saml/acs
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
- - match:
- prefix: /sso/saml/metadata
- route:
- cluster: auth
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /sso/saml/metadata
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
-
- - name: functions-v1-all
- match:
- prefix: /functions/v1/
- route:
- cluster: functions
- prefix_rewrite: /
- timeout: 150s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /functions/v1/
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
-
- - match:
- prefix: /storage/v1/
- route:
- cluster: storage
- prefix_rewrite: /
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /storage/v1
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
-
- - name: auth-v1-protected
- match:
- prefix: /auth/v1/
- route:
- cluster: auth
- prefix_rewrite: /
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /auth/v1/
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
-
- - name: rest-v1-protected
- match:
- prefix: /rest/v1/
- route:
- cluster: rest
- prefix_rewrite: /
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /rest/v1/
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
-
- - name: graphql-v1-protected
- match:
- prefix: /graphql/v1
- route:
- cluster: rest
- prefix_rewrite: /rpc/graphql
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /graphql/v1
- append_action: ADD_IF_ABSENT
- - header:
- key: Content-Profile
- value: graphql_public
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
-
- - name: realtime-v1-api-protected
- match:
- prefix: /realtime/v1/api
- route:
- cluster: realtime
- prefix_rewrite: /api
- timeout: 30s
- host_rewrite_literal: realtime-dev.briven-realtime
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /realtime/v1/api
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
-
- - name: realtime-v1-ws-protected
- match:
- prefix: /realtime/v1/
- route:
- cluster: realtime
- prefix_rewrite: /socket/
- timeout: 30s
- host_rewrite_literal: realtime-dev.briven-realtime
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /realtime/v1/
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
-
- - name: pg-protected
- match:
- prefix: /pg/
- route:
- cluster: meta
- prefix_rewrite: /
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /pg/
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
-
- - match:
- prefix: /api/mcp
- route:
- cluster: studio
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /api/mcp
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: DENY
- policies:
- deny_all:
- permissions:
- - any: true
- principals:
- - any: true
-
- - match:
- prefix: /mcp
- route:
- cluster: studio
- prefix_rewrite: /api/mcp
- timeout: 30s
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /mcp
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.basic_auth:
- '@type': >-
- type.googleapis.com/envoy.config.route.v3.FilterConfig
- disabled: true
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- # Block access to /mcp by default
- rbac:
- rules:
- action: DENY
- policies:
- deny_all:
- permissions:
- - any: true
- principals:
- - any: true
- # Enable local access (danger zone!)
- # 1. Comment out the 'rbac' block above.
- # 2. Uncomment and adjust the 'rbac' block below.
- # 3. Add or adjust your local IPs in 'principals'.
- #rbac:
- # rules:
- # action: ALLOW
- # policies:
- # allow_local:
- # permissions:
- # - any: true
- # principals:
- # - direct_remote_ip:
- # address_prefix: 127.0.0.1
- # prefix_len: 32
- # - direct_remote_ip:
- # address_prefix: ::1
- # prefix_len: 128
-
- - match:
- prefix: /
- route:
- cluster: studio
- timeout: 30s
- request_headers_to_remove:
- - authorization
- request_headers_to_add:
- - header:
- key: X-Forwarded-Prefix
- value: /
- append_action: ADD_IF_ABSENT
- typed_per_filter_config:
- envoy.filters.http.rbac:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute
- rbac:
- rules:
- action: ALLOW
- policies:
- allow_all:
- permissions:
- - any: true
- principals:
- - any: true
- http_filters:
- - name: envoy.filters.http.cors
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.cors.v3.Cors
-
- - name: envoy.filters.http.basic_auth
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.basic_auth.v3.BasicAuth
- users:
- inline_string: '${DASHBOARD_BASIC_AUTH}'
-
- # Copies ?apikey=... from the URL into the apikey header when clients omit the header.
- - name: envoy.filters.http.lua
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
- inline_code: |
- local FUNCTIONS_ROUTE = "functions-v1-all"
- local FUNCTIONS_PREFIX = "/functions/v1/"
- local function is_functions_request(request_handle, headers)
- if request_handle:streamInfo():routeName() == FUNCTIONS_ROUTE then
- return true
- end
- local path = headers:get(":path")
- if path == nil then
- return false
- end
- return string.sub(path, 1, string.len(FUNCTIONS_PREFIX)) == FUNCTIONS_PREFIX
- end
- function envoy_on_request(request_handle)
- local headers = request_handle:headers()
- if is_functions_request(request_handle, headers) then
- return
- end
- if headers:get("apikey") ~= nil then
- return
- end
- local path = headers:get(":path")
- local query_start = string.find(path, "?", 1, true)
- if query_start == nil then
- return
- end
- local query = string.sub(path, query_start + 1)
- for key, value in string.gmatch(query, "([^&]+)=([^&]*)") do
- if key == "apikey" and value ~= "" then
- headers:add("apikey", value)
- return
- end
- end
- end
- # Translates the query parameter apikey into the matching internal JWT and rewrites the URL so only JWTs propagate downstream.
- - name: envoy.filters.http.lua
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
- inline_code: |
- local FUNCTIONS_ROUTE = "functions-v1-all"
- local FUNCTIONS_PREFIX = "/functions/v1/"
- local SECRET_KEY = "${BRIVEN_SECRET_KEY}"
- local PUBLISHABLE_KEY = "${BRIVEN_PUBLISHABLE_KEY}"
- local SERVICE_ROLE_JWT = "${SERVICE_ROLE_KEY_ASYMMETRIC}"
- local ANON_JWT = "${ANON_KEY_ASYMMETRIC}"
- local TRANSLATION_ENABLED = SECRET_KEY ~= "" and PUBLISHABLE_KEY ~= "" and SERVICE_ROLE_JWT ~= "" and ANON_JWT ~= ""
- local function is_functions_request(request_handle, headers)
- if request_handle:streamInfo():routeName() == FUNCTIONS_ROUTE then
- return true
- end
- local path = headers:get(":path")
- if path == nil then
- return false
- end
- return string.sub(path, 1, string.len(FUNCTIONS_PREFIX)) == FUNCTIONS_PREFIX
- end
- local function translate_apikey(apikey)
- if apikey == nil or apikey == "" then
- return nil
- end
- if not TRANSLATION_ENABLED then
- return nil
- end
- if apikey == SECRET_KEY then
- return SERVICE_ROLE_JWT
- end
- if apikey == PUBLISHABLE_KEY then
- return ANON_JWT
- end
- return nil
- end
- local function extract_query_apikey(path)
- if path == nil or path == "" then
- return nil
- end
- local query_start = string.find(path, "?", 1, true)
- if query_start == nil then
- return nil
- end
- local query = string.sub(path, query_start + 1)
- for key, value in string.gmatch(query, "([^&]+)=([^&]*)") do
- if key == "apikey" and value ~= "" then
- return value
- end
- end
- return nil
- end
- local function replace_query_apikey(path, new_value)
- if path == nil or path == "" or new_value == nil or new_value == "" then
- return nil
- end
- local query_start = string.find(path, "?", 1, true)
- if query_start == nil then
- return nil
- end
- local base = string.sub(path, 1, query_start)
- local query = string.sub(path, query_start + 1)
- local updated = {}
- local replaced = false
- for part in string.gmatch(query, "([^&]+)") do
- local key, value = string.match(part, "([^=]+)=(.*)")
- if key == "apikey" then
- part = key .. "=" .. new_value
- replaced = true
- end
- table.insert(updated, part)
- end
- if not replaced then
- return nil
- end
- return base .. table.concat(updated, "&")
- end
- function envoy_on_request(request_handle)
- local headers = request_handle:headers()
- if is_functions_request(request_handle, headers) then
- return
- end
- local path = headers:get(":path")
- local apikey = extract_query_apikey(path)
- local translated = translate_apikey(apikey)
- if translated == nil then
- return
- end
- headers:replace("apikey", translated)
- local rewritten_path = replace_query_apikey(path, translated)
- if rewritten_path ~= nil then
- headers:replace(":path", rewritten_path)
- end
- end
- # Translates an apikey header into the appropriate internal JWT for downstream RBAC checks.
- - name: envoy.filters.http.lua
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
- inline_code: |
- local FUNCTIONS_ROUTE = "functions-v1-all"
- local FUNCTIONS_PREFIX = "/functions/v1/"
- local SECRET_KEY = "${BRIVEN_SECRET_KEY}"
- local PUBLISHABLE_KEY = "${BRIVEN_PUBLISHABLE_KEY}"
- local SERVICE_ROLE_JWT = "${SERVICE_ROLE_KEY_ASYMMETRIC}"
- local ANON_JWT = "${ANON_KEY_ASYMMETRIC}"
- local TRANSLATION_ENABLED = SECRET_KEY ~= "" and PUBLISHABLE_KEY ~= "" and SERVICE_ROLE_JWT ~= "" and ANON_JWT ~= ""
- local function is_functions_request(request_handle, headers)
- if request_handle:streamInfo():routeName() == FUNCTIONS_ROUTE then
- return true
- end
- local path = headers:get(":path")
- if path == nil then
- return false
- end
- return string.sub(path, 1, string.len(FUNCTIONS_PREFIX)) == FUNCTIONS_PREFIX
- end
- local function translate_apikey(apikey)
- if apikey == nil or apikey == "" then
- return nil
- end
- if not TRANSLATION_ENABLED then
- return nil
- end
- if apikey == SECRET_KEY then
- return SERVICE_ROLE_JWT
- end
- if apikey == PUBLISHABLE_KEY then
- return ANON_JWT
- end
- return nil
- end
- function envoy_on_request(request_handle)
- local headers = request_handle:headers()
- if is_functions_request(request_handle, headers) then
- return
- end
- local translated = translate_apikey(headers:get("apikey"))
- if translated ~= nil and translated ~= "" then
- headers:replace("apikey", translated)
- end
- end
- # Mirrors apikey into x-api-key for realtime WS compatibility.
- - name: envoy.filters.http.lua
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
- inline_code: |
- local REALTIME_WS_ROUTE = "realtime-v1-ws-protected"
- function envoy_on_request(request_handle)
- local route_name = request_handle:streamInfo():routeName()
- if route_name ~= REALTIME_WS_ROUTE then
- return
- end
- local headers = request_handle:headers()
- local apikey = headers:get("apikey")
- if apikey == nil or apikey == "" then
- return
- end
- headers:replace("x-api-key", apikey)
- end
- # Synthesizes an Authorization header (Bearer …) from apikey when callers don’t provide a real JWT header.
- - name: envoy.filters.http.lua
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
- inline_code: |
- local FUNCTIONS_ROUTE = "functions-v1-all"
- local FUNCTIONS_PREFIX = "/functions/v1/"
- local REALTIME_WS_ROUTE = "realtime-v1-ws-protected"
- local function is_functions_request(request_handle, headers)
- if request_handle:streamInfo():routeName() == FUNCTIONS_ROUTE then
- return true
- end
- local path = headers:get(":path")
- if path == nil then
- return false
- end
- return string.sub(path, 1, string.len(FUNCTIONS_PREFIX)) == FUNCTIONS_PREFIX
- end
- local function has_real_jwt(auth_header)
- if auth_header == nil or auth_header == "" then
- return false
- end
- if string.sub(auth_header, 1, 7) ~= "Bearer " then
- return false
- end
- return string.sub(auth_header, 1, 10) ~= "Bearer sb_"
- end
- local function format_authorization(value)
- if value == nil or value == "" then
- return nil
- end
- if string.sub(value, 1, 7) == "Bearer " then
- return value
- end
- return "Bearer " .. value
- end
- function envoy_on_request(request_handle)
- local headers = request_handle:headers()
- if request_handle:streamInfo():routeName() == REALTIME_WS_ROUTE then
- return
- end
- if is_functions_request(request_handle, headers) then
- return
- end
- if has_real_jwt(headers:get("authorization")) then
- return
- end
- local apikey = headers:get("apikey")
- local authorization_value = format_authorization(apikey)
- if authorization_value ~= nil then
- headers:replace("authorization", authorization_value)
- end
- end
- # Returns 401 for missing/invalid API keys on protected API routes.
- - name: envoy.filters.http.lua
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
- inline_code: |
- local ANON_KEY = "${ANON_KEY}"
- local SERVICE_ROLE_KEY = "${SERVICE_ROLE_KEY}"
- local BRIVEN_PUBLISHABLE_KEY = "${BRIVEN_PUBLISHABLE_KEY}"
- local BRIVEN_SECRET_KEY = "${BRIVEN_SECRET_KEY}"
- local ANON_KEY_ASYMMETRIC = "${ANON_KEY_ASYMMETRIC}"
- local SERVICE_ROLE_KEY_ASYMMETRIC = "${SERVICE_ROLE_KEY_ASYMMETRIC}"
- local TRANSLATION_ENABLED = BRIVEN_SECRET_KEY ~= "" and BRIVEN_PUBLISHABLE_KEY ~= "" and SERVICE_ROLE_KEY_ASYMMETRIC ~= "" and ANON_KEY_ASYMMETRIC ~= ""
- local PROTECTED_ROUTES = {
- ["auth-v1-protected"] = true,
- ["rest-v1-protected"] = true,
- ["graphql-v1-protected"] = true,
- ["realtime-v1-api-protected"] = true,
- ["realtime-v1-ws-protected"] = true,
- ["pg-protected"] = true,
- }
- local function is_protected_route(route_name)
- if route_name == nil or route_name == "" then
- return false
- end
- return PROTECTED_ROUTES[route_name] == true
- end
- local function is_valid_apikey(apikey)
- if apikey == nil or apikey == "" then
- return false
- end
- if SERVICE_ROLE_KEY ~= "" and apikey == SERVICE_ROLE_KEY then
- return true
- end
- if ANON_KEY ~= "" and apikey == ANON_KEY then
- return true
- end
- if TRANSLATION_ENABLED and apikey == SERVICE_ROLE_KEY_ASYMMETRIC then
- return true
- end
- if TRANSLATION_ENABLED and apikey == ANON_KEY_ASYMMETRIC then
- return true
- end
- return false
- end
- function envoy_on_request(request_handle)
- local headers = request_handle:headers()
- local route_name = request_handle:streamInfo():routeName()
- if not is_protected_route(route_name) then
- return
- end
- if is_valid_apikey(headers:get("apikey")) then
- return
- end
- request_handle:respond({
- [":status"] = "401",
- ["content-type"] = "text/plain",
- }, "Unauthorized")
- end
- - name: envoy.filters.http.rbac
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC
- rules:
- action: ALLOW
- policies:
- admin:
- permissions:
- - url_path:
- path:
- prefix: /pg/
- principals:
- - header:
- name: apikey
- string_match:
- exact: '${SERVICE_ROLE_KEY}'
- - header:
- name: apikey
- string_match:
- exact: '${SERVICE_ROLE_KEY_ASYMMETRIC}'
- apikey:
- permissions:
- - url_path:
- path:
- prefix: /auth/v1/
- - url_path:
- path:
- prefix: /rest/v1/
- - url_path:
- path:
- prefix: /realtime/v1/api
- - url_path:
- path:
- prefix: /realtime/v1/
- - url_path:
- path:
- prefix: /graphql/v1
- principals:
- - header:
- name: apikey
- string_match:
- exact: '${SERVICE_ROLE_KEY}'
- - header:
- name: apikey
- string_match:
- exact: '${ANON_KEY}'
- - header:
- name: apikey
- string_match:
- exact: '${SERVICE_ROLE_KEY_ASYMMETRIC}'
- - header:
- name: apikey
- string_match:
- exact: '${ANON_KEY_ASYMMETRIC}'
- - name: envoy.filters.http.router
- typed_config:
- '@type': >-
- type.googleapis.com/envoy.extensions.filters.http.router.v3.Router
|