java.lang.Object
com.google.protobuf.AbstractMessageLite
com.google.protobuf.AbstractMessage
com.google.protobuf.GeneratedMessageV3
io.envoyproxy.envoy.extensions.filters.network.rbac.v3.RBAC
All Implemented Interfaces:
com.google.protobuf.Message, com.google.protobuf.MessageLite, com.google.protobuf.MessageLiteOrBuilder, com.google.protobuf.MessageOrBuilder, RBACOrBuilder, Serializable

public final class RBAC extends com.google.protobuf.GeneratedMessageV3 implements RBACOrBuilder
 RBAC network filter config.

 Header should not be used in rules/shadow_rules in RBAC network filter as
 this information is only available in :ref:`RBAC http filter <config_http_filters_rbac>`.
 [#next-free-field: 9]
 
Protobuf type envoy.extensions.filters.network.rbac.v3.RBAC
See Also:
  • Nested Class Summary

    Nested Classes
    Modifier and Type
    Class
    Description
    static final class 
    RBAC network filter config.
    static enum 
    Protobuf enum envoy.extensions.filters.network.rbac.v3.RBAC.EnforcementType

    Nested classes/interfaces inherited from class com.google.protobuf.GeneratedMessageV3

    com.google.protobuf.GeneratedMessageV3.BuilderParent, com.google.protobuf.GeneratedMessageV3.ExtendableBuilder<MessageT extends com.google.protobuf.GeneratedMessageV3.ExtendableMessage<MessageT>,BuilderT extends com.google.protobuf.GeneratedMessageV3.ExtendableBuilder<MessageT,BuilderT>>, com.google.protobuf.GeneratedMessageV3.ExtendableMessage<MessageT extends com.google.protobuf.GeneratedMessageV3.ExtendableMessage<MessageT>>, com.google.protobuf.GeneratedMessageV3.ExtendableMessageOrBuilder<MessageT extends com.google.protobuf.GeneratedMessageV3.ExtendableMessage<MessageT>>, com.google.protobuf.GeneratedMessageV3.FieldAccessorTable, com.google.protobuf.GeneratedMessageV3.UnusedPrivateParameter

    Nested classes/interfaces inherited from class com.google.protobuf.AbstractMessageLite

    com.google.protobuf.AbstractMessageLite.InternalOneOfEnum
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final int
     
    static final int
     
    static final int
     
    static final int
     
    static final int
     
    static final int
     
    static final int
     
    static final int
     

    Fields inherited from class com.google.protobuf.GeneratedMessageV3

    alwaysUseFieldBuilders, unknownFields

    Fields inherited from class com.google.protobuf.AbstractMessage

    memoizedSize

    Fields inherited from class com.google.protobuf.AbstractMessageLite

    memoizedHashCode
  • Method Summary

    Modifier and Type
    Method
    Description
    boolean
     
    static RBAC
     
     
    com.google.protobuf.Duration
    Delay the specified duration before closing the connection when the policy evaluation result is ``DENY``.
    com.google.protobuf.DurationOrBuilder
    Delay the specified duration before closing the connection when the policy evaluation result is ``DENY``.
    static final com.google.protobuf.Descriptors.Descriptor
     
    RBAC enforcement strategy.
    int
    RBAC enforcement strategy.
    The match tree to use when resolving RBAC action for incoming connections.
    The match tree to use when resolving RBAC action for incoming connections.
    com.google.protobuf.Parser<RBAC>
     
    Specify the RBAC rules to be applied globally.
    Specify the RBAC rules to be applied globally.
    int
     
    The match tree to use for emitting stats and logs which can be used for rule testing for incoming connections.
    The match tree to use for emitting stats and logs which can be used for rule testing for incoming connections.
    Shadow rules are not enforced by the filter but will emit stats and logs and can be used for rule testing.
    Shadow rules are not enforced by the filter but will emit stats and logs and can be used for rule testing.
    If specified, shadow rules will emit stats with the given prefix.
    com.google.protobuf.ByteString
    If specified, shadow rules will emit stats with the given prefix.
    The prefix to use when emitting statistics.
    com.google.protobuf.ByteString
    The prefix to use when emitting statistics.
    boolean
    Delay the specified duration before closing the connection when the policy evaluation result is ``DENY``.
    int
     
    boolean
    The match tree to use when resolving RBAC action for incoming connections.
    boolean
    Specify the RBAC rules to be applied globally.
    boolean
    The match tree to use for emitting stats and logs which can be used for rule testing for incoming connections.
    boolean
    Shadow rules are not enforced by the filter but will emit stats and logs and can be used for rule testing.
    protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable
     
    final boolean
     
     
    newBuilder(RBAC prototype)
     
     
    protected RBAC.Builder
    newBuilderForType(com.google.protobuf.GeneratedMessageV3.BuilderParent parent)
     
    protected Object
    newInstance(com.google.protobuf.GeneratedMessageV3.UnusedPrivateParameter unused)
     
    static RBAC
     
    static RBAC
    parseDelimitedFrom(InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
     
    static RBAC
    parseFrom(byte[] data)
     
    static RBAC
    parseFrom(byte[] data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
     
    static RBAC
    parseFrom(com.google.protobuf.ByteString data)
     
    static RBAC
    parseFrom(com.google.protobuf.ByteString data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
     
    static RBAC
    parseFrom(com.google.protobuf.CodedInputStream input)
     
    static RBAC
    parseFrom(com.google.protobuf.CodedInputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
     
    static RBAC
     
    static RBAC
    parseFrom(InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
     
    static RBAC
     
    static RBAC
    parseFrom(ByteBuffer data, com.google.protobuf.ExtensionRegistryLite extensionRegistry)
     
    static com.google.protobuf.Parser<RBAC>
     
     
    void
    writeTo(com.google.protobuf.CodedOutputStream output)
     

    Methods inherited from class com.google.protobuf.GeneratedMessageV3

    canUseUnsafe, computeStringSize, computeStringSizeNoTag, emptyBooleanList, emptyDoubleList, emptyFloatList, emptyIntList, emptyList, emptyLongList, getAllFields, getDescriptorForType, getField, getOneofFieldDescriptor, getRepeatedField, getRepeatedFieldCount, getUnknownFields, hasField, hasOneof, internalGetMapField, internalGetMapFieldReflection, isStringEmpty, makeExtensionsImmutable, makeMutableCopy, makeMutableCopy, mergeFromAndMakeImmutableInternal, mutableCopy, mutableCopy, mutableCopy, mutableCopy, mutableCopy, newBooleanList, newBuilderForType, newDoubleList, newFloatList, newIntList, newLongList, parseDelimitedWithIOException, parseDelimitedWithIOException, parseUnknownField, parseUnknownFieldProto3, parseWithIOException, parseWithIOException, parseWithIOException, parseWithIOException, serializeBooleanMapTo, serializeIntegerMapTo, serializeLongMapTo, serializeStringMapTo, writeReplace, writeString, writeStringNoTag

    Methods inherited from class com.google.protobuf.AbstractMessage

    findInitializationErrors, getInitializationErrorString, hashBoolean, hashEnum, hashEnumList, hashFields, hashLong, toString

    Methods inherited from class com.google.protobuf.AbstractMessageLite

    addAll, addAll, checkByteStringIsUtf8, toByteArray, toByteString, writeDelimitedTo, writeTo

    Methods inherited from class java.lang.Object

    clone, finalize, getClass, notify, notifyAll, wait, wait, wait

    Methods inherited from interface com.google.protobuf.MessageLite

    toByteArray, toByteString, writeDelimitedTo, writeTo

    Methods inherited from interface com.google.protobuf.MessageOrBuilder

    findInitializationErrors, getAllFields, getDescriptorForType, getField, getInitializationErrorString, getOneofFieldDescriptor, getRepeatedField, getRepeatedFieldCount, getUnknownFields, hasField, hasOneof
  • Field Details

    • RULES_FIELD_NUMBER

      public static final int RULES_FIELD_NUMBER
      See Also:
    • MATCHER_FIELD_NUMBER

      public static final int MATCHER_FIELD_NUMBER
      See Also:
    • SHADOW_RULES_FIELD_NUMBER

      public static final int SHADOW_RULES_FIELD_NUMBER
      See Also:
    • SHADOW_MATCHER_FIELD_NUMBER

      public static final int SHADOW_MATCHER_FIELD_NUMBER
      See Also:
    • SHADOW_RULES_STAT_PREFIX_FIELD_NUMBER

      public static final int SHADOW_RULES_STAT_PREFIX_FIELD_NUMBER
      See Also:
    • STAT_PREFIX_FIELD_NUMBER

      public static final int STAT_PREFIX_FIELD_NUMBER
      See Also:
    • ENFORCEMENT_TYPE_FIELD_NUMBER

      public static final int ENFORCEMENT_TYPE_FIELD_NUMBER
      See Also:
    • DELAY_DENY_FIELD_NUMBER

      public static final int DELAY_DENY_FIELD_NUMBER
      See Also:
  • Method Details

    • newInstance

      protected Object newInstance(com.google.protobuf.GeneratedMessageV3.UnusedPrivateParameter unused)
      Overrides:
      newInstance in class com.google.protobuf.GeneratedMessageV3
    • getDescriptor

      public static final com.google.protobuf.Descriptors.Descriptor getDescriptor()
    • internalGetFieldAccessorTable

      protected com.google.protobuf.GeneratedMessageV3.FieldAccessorTable internalGetFieldAccessorTable()
      Specified by:
      internalGetFieldAccessorTable in class com.google.protobuf.GeneratedMessageV3
    • hasRules

      public boolean hasRules()
       Specify the RBAC rules to be applied globally.
       If absent, no enforcing RBAC policy will be applied.
       If present and empty, DENY.
       If both rules and matcher are configured, rules will be ignored.
       
      .envoy.config.rbac.v3.RBAC rules = 1 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      hasRules in interface RBACOrBuilder
      Returns:
      Whether the rules field is set.
    • getRules

      public RBAC getRules()
       Specify the RBAC rules to be applied globally.
       If absent, no enforcing RBAC policy will be applied.
       If present and empty, DENY.
       If both rules and matcher are configured, rules will be ignored.
       
      .envoy.config.rbac.v3.RBAC rules = 1 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getRules in interface RBACOrBuilder
      Returns:
      The rules.
    • getRulesOrBuilder

      public RBACOrBuilder getRulesOrBuilder()
       Specify the RBAC rules to be applied globally.
       If absent, no enforcing RBAC policy will be applied.
       If present and empty, DENY.
       If both rules and matcher are configured, rules will be ignored.
       
      .envoy.config.rbac.v3.RBAC rules = 1 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getRulesOrBuilder in interface RBACOrBuilder
    • hasMatcher

      public boolean hasMatcher()
       The match tree to use when resolving RBAC action for incoming connections. Connections do
       not match any matcher will be denied.
       If absent, no enforcing RBAC matcher will be applied.
       If present and empty, deny all connections.
       
      .xds.type.matcher.v3.Matcher matcher = 6 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      hasMatcher in interface RBACOrBuilder
      Returns:
      Whether the matcher field is set.
    • getMatcher

      public Matcher getMatcher()
       The match tree to use when resolving RBAC action for incoming connections. Connections do
       not match any matcher will be denied.
       If absent, no enforcing RBAC matcher will be applied.
       If present and empty, deny all connections.
       
      .xds.type.matcher.v3.Matcher matcher = 6 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getMatcher in interface RBACOrBuilder
      Returns:
      The matcher.
    • getMatcherOrBuilder

      public MatcherOrBuilder getMatcherOrBuilder()
       The match tree to use when resolving RBAC action for incoming connections. Connections do
       not match any matcher will be denied.
       If absent, no enforcing RBAC matcher will be applied.
       If present and empty, deny all connections.
       
      .xds.type.matcher.v3.Matcher matcher = 6 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getMatcherOrBuilder in interface RBACOrBuilder
    • hasShadowRules

      public boolean hasShadowRules()
       Shadow rules are not enforced by the filter but will emit stats and logs
       and can be used for rule testing.
       If absent, no shadow RBAC policy will be applied.
       If both shadow rules and shadow matcher are configured, shadow rules will be ignored.
       
      .envoy.config.rbac.v3.RBAC shadow_rules = 2 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      hasShadowRules in interface RBACOrBuilder
      Returns:
      Whether the shadowRules field is set.
    • getShadowRules

      public RBAC getShadowRules()
       Shadow rules are not enforced by the filter but will emit stats and logs
       and can be used for rule testing.
       If absent, no shadow RBAC policy will be applied.
       If both shadow rules and shadow matcher are configured, shadow rules will be ignored.
       
      .envoy.config.rbac.v3.RBAC shadow_rules = 2 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getShadowRules in interface RBACOrBuilder
      Returns:
      The shadowRules.
    • getShadowRulesOrBuilder

      public RBACOrBuilder getShadowRulesOrBuilder()
       Shadow rules are not enforced by the filter but will emit stats and logs
       and can be used for rule testing.
       If absent, no shadow RBAC policy will be applied.
       If both shadow rules and shadow matcher are configured, shadow rules will be ignored.
       
      .envoy.config.rbac.v3.RBAC shadow_rules = 2 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getShadowRulesOrBuilder in interface RBACOrBuilder
    • hasShadowMatcher

      public boolean hasShadowMatcher()
       The match tree to use for emitting stats and logs which can be used for rule testing for
       incoming connections.
       If absent, no shadow matcher will be applied.
       
      .xds.type.matcher.v3.Matcher shadow_matcher = 7 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      hasShadowMatcher in interface RBACOrBuilder
      Returns:
      Whether the shadowMatcher field is set.
    • getShadowMatcher

      public Matcher getShadowMatcher()
       The match tree to use for emitting stats and logs which can be used for rule testing for
       incoming connections.
       If absent, no shadow matcher will be applied.
       
      .xds.type.matcher.v3.Matcher shadow_matcher = 7 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getShadowMatcher in interface RBACOrBuilder
      Returns:
      The shadowMatcher.
    • getShadowMatcherOrBuilder

      public MatcherOrBuilder getShadowMatcherOrBuilder()
       The match tree to use for emitting stats and logs which can be used for rule testing for
       incoming connections.
       If absent, no shadow matcher will be applied.
       
      .xds.type.matcher.v3.Matcher shadow_matcher = 7 [(.udpa.annotations.field_migrate) = { ... }
      Specified by:
      getShadowMatcherOrBuilder in interface RBACOrBuilder
    • getShadowRulesStatPrefix

      public String getShadowRulesStatPrefix()
       If specified, shadow rules will emit stats with the given prefix.
       This is useful to distinguish the stat when there are more than 1 RBAC filter configured with
       shadow rules.
       
      string shadow_rules_stat_prefix = 5;
      Specified by:
      getShadowRulesStatPrefix in interface RBACOrBuilder
      Returns:
      The shadowRulesStatPrefix.
    • getShadowRulesStatPrefixBytes

      public com.google.protobuf.ByteString getShadowRulesStatPrefixBytes()
       If specified, shadow rules will emit stats with the given prefix.
       This is useful to distinguish the stat when there are more than 1 RBAC filter configured with
       shadow rules.
       
      string shadow_rules_stat_prefix = 5;
      Specified by:
      getShadowRulesStatPrefixBytes in interface RBACOrBuilder
      Returns:
      The bytes for shadowRulesStatPrefix.
    • getStatPrefix

      public String getStatPrefix()
       The prefix to use when emitting statistics.
       
      string stat_prefix = 3 [(.validate.rules) = { ... }
      Specified by:
      getStatPrefix in interface RBACOrBuilder
      Returns:
      The statPrefix.
    • getStatPrefixBytes

      public com.google.protobuf.ByteString getStatPrefixBytes()
       The prefix to use when emitting statistics.
       
      string stat_prefix = 3 [(.validate.rules) = { ... }
      Specified by:
      getStatPrefixBytes in interface RBACOrBuilder
      Returns:
      The bytes for statPrefix.
    • getEnforcementTypeValue

      public int getEnforcementTypeValue()
       RBAC enforcement strategy. By default RBAC will be enforced only once
       when the first byte of data arrives from the downstream. When used in
       conjunction with filters that emit dynamic metadata after decoding
       every payload (e.g., Mongo, MySQL, Kafka) set the enforcement type to
       CONTINUOUS to enforce RBAC policies on every message boundary.
       
      .envoy.extensions.filters.network.rbac.v3.RBAC.EnforcementType enforcement_type = 4;
      Specified by:
      getEnforcementTypeValue in interface RBACOrBuilder
      Returns:
      The enum numeric value on the wire for enforcementType.
    • getEnforcementType

      public RBAC.EnforcementType getEnforcementType()
       RBAC enforcement strategy. By default RBAC will be enforced only once
       when the first byte of data arrives from the downstream. When used in
       conjunction with filters that emit dynamic metadata after decoding
       every payload (e.g., Mongo, MySQL, Kafka) set the enforcement type to
       CONTINUOUS to enforce RBAC policies on every message boundary.
       
      .envoy.extensions.filters.network.rbac.v3.RBAC.EnforcementType enforcement_type = 4;
      Specified by:
      getEnforcementType in interface RBACOrBuilder
      Returns:
      The enforcementType.
    • hasDelayDeny

      public boolean hasDelayDeny()
       Delay the specified duration before closing the connection when the policy evaluation
       result is ``DENY``. If this is not present, the connection will be closed immediately.
       This is useful to provide a better protection for Envoy against clients that retries
       aggressively when the connection is rejected by the RBAC filter.
       
      .google.protobuf.Duration delay_deny = 8;
      Specified by:
      hasDelayDeny in interface RBACOrBuilder
      Returns:
      Whether the delayDeny field is set.
    • getDelayDeny

      public com.google.protobuf.Duration getDelayDeny()
       Delay the specified duration before closing the connection when the policy evaluation
       result is ``DENY``. If this is not present, the connection will be closed immediately.
       This is useful to provide a better protection for Envoy against clients that retries
       aggressively when the connection is rejected by the RBAC filter.
       
      .google.protobuf.Duration delay_deny = 8;
      Specified by:
      getDelayDeny in interface RBACOrBuilder
      Returns:
      The delayDeny.
    • getDelayDenyOrBuilder

      public com.google.protobuf.DurationOrBuilder getDelayDenyOrBuilder()
       Delay the specified duration before closing the connection when the policy evaluation
       result is ``DENY``. If this is not present, the connection will be closed immediately.
       This is useful to provide a better protection for Envoy against clients that retries
       aggressively when the connection is rejected by the RBAC filter.
       
      .google.protobuf.Duration delay_deny = 8;
      Specified by:
      getDelayDenyOrBuilder in interface RBACOrBuilder
    • isInitialized

      public final boolean isInitialized()
      Specified by:
      isInitialized in interface com.google.protobuf.MessageLiteOrBuilder
      Overrides:
      isInitialized in class com.google.protobuf.GeneratedMessageV3
    • writeTo

      public void writeTo(com.google.protobuf.CodedOutputStream output) throws IOException
      Specified by:
      writeTo in interface com.google.protobuf.MessageLite
      Overrides:
      writeTo in class com.google.protobuf.GeneratedMessageV3
      Throws:
      IOException
    • getSerializedSize

      public int getSerializedSize()
      Specified by:
      getSerializedSize in interface com.google.protobuf.MessageLite
      Overrides:
      getSerializedSize in class com.google.protobuf.GeneratedMessageV3
    • equals

      public boolean equals(Object obj)
      Specified by:
      equals in interface com.google.protobuf.Message
      Overrides:
      equals in class com.google.protobuf.AbstractMessage
    • hashCode

      public int hashCode()
      Specified by:
      hashCode in interface com.google.protobuf.Message
      Overrides:
      hashCode in class com.google.protobuf.AbstractMessage
    • parseFrom

      public static RBAC parseFrom(ByteBuffer data) throws com.google.protobuf.InvalidProtocolBufferException
      Throws:
      com.google.protobuf.InvalidProtocolBufferException
    • parseFrom

      public static RBAC parseFrom(ByteBuffer data, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws com.google.protobuf.InvalidProtocolBufferException
      Throws:
      com.google.protobuf.InvalidProtocolBufferException
    • parseFrom

      public static RBAC parseFrom(com.google.protobuf.ByteString data) throws com.google.protobuf.InvalidProtocolBufferException
      Throws:
      com.google.protobuf.InvalidProtocolBufferException
    • parseFrom

      public static RBAC parseFrom(com.google.protobuf.ByteString data, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws com.google.protobuf.InvalidProtocolBufferException
      Throws:
      com.google.protobuf.InvalidProtocolBufferException
    • parseFrom

      public static RBAC parseFrom(byte[] data) throws com.google.protobuf.InvalidProtocolBufferException
      Throws:
      com.google.protobuf.InvalidProtocolBufferException
    • parseFrom

      public static RBAC parseFrom(byte[] data, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws com.google.protobuf.InvalidProtocolBufferException
      Throws:
      com.google.protobuf.InvalidProtocolBufferException
    • parseFrom

      public static RBAC parseFrom(InputStream input) throws IOException
      Throws:
      IOException
    • parseFrom

      public static RBAC parseFrom(InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws IOException
      Throws:
      IOException
    • parseDelimitedFrom

      public static RBAC parseDelimitedFrom(InputStream input) throws IOException
      Throws:
      IOException
    • parseDelimitedFrom

      public static RBAC parseDelimitedFrom(InputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws IOException
      Throws:
      IOException
    • parseFrom

      public static RBAC parseFrom(com.google.protobuf.CodedInputStream input) throws IOException
      Throws:
      IOException
    • parseFrom

      public static RBAC parseFrom(com.google.protobuf.CodedInputStream input, com.google.protobuf.ExtensionRegistryLite extensionRegistry) throws IOException
      Throws:
      IOException
    • newBuilderForType

      public RBAC.Builder newBuilderForType()
      Specified by:
      newBuilderForType in interface com.google.protobuf.Message
      Specified by:
      newBuilderForType in interface com.google.protobuf.MessageLite
    • newBuilder

      public static RBAC.Builder newBuilder()
    • newBuilder

      public static RBAC.Builder newBuilder(RBAC prototype)
    • toBuilder

      public RBAC.Builder toBuilder()
      Specified by:
      toBuilder in interface com.google.protobuf.Message
      Specified by:
      toBuilder in interface com.google.protobuf.MessageLite
    • newBuilderForType

      protected RBAC.Builder newBuilderForType(com.google.protobuf.GeneratedMessageV3.BuilderParent parent)
      Specified by:
      newBuilderForType in class com.google.protobuf.GeneratedMessageV3
    • getDefaultInstance

      public static RBAC getDefaultInstance()
    • parser

      public static com.google.protobuf.Parser<RBAC> parser()
    • getParserForType

      public com.google.protobuf.Parser<RBAC> getParserForType()
      Specified by:
      getParserForType in interface com.google.protobuf.Message
      Specified by:
      getParserForType in interface com.google.protobuf.MessageLite
      Overrides:
      getParserForType in class com.google.protobuf.GeneratedMessageV3
    • getDefaultInstanceForType

      public RBAC getDefaultInstanceForType()
      Specified by:
      getDefaultInstanceForType in interface com.google.protobuf.MessageLiteOrBuilder
      Specified by:
      getDefaultInstanceForType in interface com.google.protobuf.MessageOrBuilder