Widen mTLS PERMISSIVE/AuthorizationPolicy to cover port 61432 too

home's own authentik pods reach ha-authentik-postgres via the CoreDNS
rewrite on port 61432 (not just external traffic via NodePort on 5432/
61432) - discovered live that Istio ambient's port-level mTLS/L4
authorization enforcement is keyed on the port actually dialed (61432
here), not just the pod's real containerPort (5432) traffic eventually
reaches after Service translation. The existing port-5432-only rules
(from the streaming-replication fix) didn't cover this in-cluster path,
surfacing as 'server closed the connection unexpectedly' from home's own
authentik-worker pod.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Scooby Husky
2026-08-20 18:51:42 -05:00
co-authored by Claude Sonnet 5
parent 185e9c292e
commit c6d4294be6
2 changed files with 12 additions and 0 deletions
@@ -38,3 +38,14 @@ spec:
portLevelMtls: portLevelMtls:
"5432": "5432":
mode: PERMISSIVE mode: PERMISSIVE
# Multi-site active failover pilot, floating hostname (see
# infrastructure/authentik/manifests/ha-postgres-nodeport.yaml): the
# ha-authentik-postgres Service also listens on 61432 (-> targetPort
# 5432, same pods) so home's own pods can reach it via the
# pg-authentik.ha.huskypup.net CoreDNS rewrite on the same port the
# app tier is configured with externally. Needed its own PERMISSIVE
# entry - confirmed live 2026-08-20 that ambient's port-level mTLS
# enforcement is keyed on the port actually dialed (61432), not just
# the pod's real containerPort (5432) it eventually reaches.
"61432":
mode: PERMISSIVE
@@ -131,6 +131,7 @@ spec:
- operation: - operation:
ports: ports:
- "5432" - "5432"
- "61432" # floating-hostname port, see ha-postgres-peerauth.yaml
--- ---
# --- Grafana: Allow ingress + Prometheus datasource queries + scraping --- # --- Grafana: Allow ingress + Prometheus datasource queries + scraping ---