@Generated(value="jsii-pacmak/1.74.0 (build 6d08790)",
date="2023-03-22T19:35:48.679Z")
public interface TlsValidation
Example:
Mesh mesh; Service service; VirtualNode node = VirtualNode.Builder.create(this, "node") .mesh(mesh) .serviceDiscovery(ServiceDiscovery.cloudMap(service)) .listeners(List.of(VirtualNodeListener.http(HttpVirtualNodeListenerOptions.builder() .port(8080) .healthCheck(HealthCheck.http(HttpHealthCheckOptions.builder() .healthyThreshold(3) .interval(Duration.seconds(5)) .path("/ping") .timeout(Duration.seconds(2)) .unhealthyThreshold(2) .build())) .timeout(HttpTimeout.builder() .idle(Duration.seconds(5)) .build()) .build()))) .backendDefaults(BackendDefaults.builder() .tlsClientPolicy(TlsClientPolicy.builder() .validation(TlsValidation.builder() .trust(TlsValidationTrust.file("/keys/local_cert_chain.pem")) .build()) .build()) .build()) .accessLog(AccessLog.fromFilePath("/dev/stdout")) .build(); Tags.of(node).add("Environment", "Dev");
Modifier and Type | Interface and Description |
---|---|
static class |
TlsValidation.Builder
A builder for
TlsValidation |
static class |
TlsValidation.Jsii$Proxy
An implementation for
TlsValidation |
Modifier and Type | Method and Description |
---|---|
static TlsValidation.Builder |
builder() |
default SubjectAlternativeNames |
getSubjectAlternativeNames()
Represents the subject alternative names (SANs) secured by the certificate.
|
TlsValidationTrust |
getTrust()
Reference to where to retrieve the trust chain.
|
TlsValidationTrust getTrust()
default SubjectAlternativeNames getSubjectAlternativeNames()
SANs must be in the FQDN or URI format.
Default: - If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration.
static TlsValidation.Builder builder()
TlsValidation.Builder
of TlsValidation