Skip to content

feat: add TEG ExtendedSecurityPolicy WAF backend for TrafficProtectionPolicy - #141

Draft
zachsmith1 wants to merge 3 commits into
mainfrom
feat/teg-esp-waf-backend
Draft

zachsmith1 wants to merge 3 commits into
mainfrom
feat/teg-esp-waf-backend

Conversation

@zachsmith1

Copy link
Copy Markdown
Contributor

Summary

Adds teg-esp as an alternative WAF backend for the TrafficProtectionPolicy controller, enabling NSO to emit TEG ExtendedSecurityPolicy resources instead of EnvoyPatchPolicy + Coraza Go filter.

Tracking issue: datum-cloud/infra#2135

  • New config field gateway.coraza.backend (coraza-epp default | teg-esp) switches which downstream resource is emitted — no behavioral change unless explicitly set
  • teg-esp mode emits one teg.tetrate.io/v1alpha1 ExtendedSecurityPolicy per upstream Gateway, targeting the corresponding downstream Gateway by name, with WAF directives rendered as a flat SecLang string in spec.waf.directives
  • coraza-epp mode (default) is unchanged — existing EPP path, cert/listener readiness checks, coraza-tcp-80 listener filter EPP all unaffected
  • CRD validation updated to restrict targetRefs[*].kind to Gateway or GatewayClass only (removes HTTPRoute), matching ESP's per-gateway granularity — run make manifests to regenerate the CRD
  • Stale cleanup in teg-esp mode uses label selector (tppManagedLabel) rather than name prefix, since ESPs are namespaced and not shared with other controllers

What's not in this PR

  • Infra-side changes (removing coraza-tcp-80 EPP, switching Envoy image from contrib to Tetrate image) — those are separate
  • Tetrate registry credentials for the private Envoy image — blocked on Tetrate

Test plan

  • TestGetDesiredExtendedSecurityPolicies — 11 subtests covering basic ESP creation, all three modes, paranoia/threshold values, rule exclusions, route-level attachment skipping, name/namespace/targetRef shape
  • TestTPPReconcileStaleCleanupTEGMode — verifies labeled stale ESPs are deleted, unlabeled ESPs are preserved
  • TestTPPReconcileStaleCleanupPreservesConnectorEPPs — existing regression test still passes on the coraza-epp path
  • All existing attachment/readiness/status tests unaffected

🤖 Generated with Claude Code

@zachsmith1
zachsmith1 force-pushed the feat/teg-esp-waf-backend branch from b236393 to a3c9212 Compare April 23, 2026 21:16
…nPolicy

Adds a new teg-esp WAF backend mode to the TrafficProtectionPolicy
controller that emits ExtendedSecurityPolicy resources
(teg.tetrate.io/v1alpha1) for the Tetrate Enterprise Gateway WAF instead
of the existing Coraza Go filter + EnvoyPatchPolicy approach.

Controlled by gateway.coraza.backend in operator config:
- coraza-epp (default): existing EPP path, no behavioral change
- teg-esp: emits one ExtendedSecurityPolicy per Gateway targeting
  the downstream Gateway by name, with WAF directives as a flat
  SecLang string in spec.waf.directives

Also restricts TPP targetRefs to Gateway/GatewayClass only (removes
HTTPRoute), matching the per-gateway granularity of ESP, and regenerates
the CRD manifest accordingly.
@zachsmith1
zachsmith1 force-pushed the feat/teg-esp-waf-backend branch from a3c9212 to 622ad24 Compare April 23, 2026 21:17
zachsmith1 and others added 2 commits April 23, 2026 14:25
- add isTEGMode comment
- fix error guard on ESP stale-cleanup List (drop !IsNotFound)
- remove unreachable len==0 guard in getDesiredExtendedSecurityPolicies
- fix misleading deduplication comment
- introduce tppManagedLabelValue constant (goconst lint)
- clean up legacy tpp-* EPPs when running in teg-esp mode (migration)
- fix TestGetDesiredEnvoyPatchPolicies: use tppEnvoyPatchPolicyPrefix constant
- fix TestTPPReconcileStaleCleanupTEGMode: register envoy scheme for migration
- add TestTPPReconcileEPPToESPMigration covering coraza-epp → teg-esp switch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant