Istio RequestAuthentication API

JWT-based request authentication policies

Documentation

Specifications

Schemas & Data

Other Resources

OpenAPI Specification

istio-requestauthentication-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Istio Extensions AuthorizationPolicy RequestAuthentication API
  description: The Istio Extensions API (extensions.istio.io) provides configuration resources for extending the Istio service mesh with custom functionality. The WasmPlugin resource enables deploying WebAssembly (Wasm) modules as plugins to the Envoy sidecar proxies, allowing custom processing of network traffic at various phases of the request lifecycle. These resources are defined as Kubernetes Custom Resource Definitions (CRDs) and are accessed via the Kubernetes API server.
  version: v1alpha1
  contact:
    name: Istio
    url: https://istio.io/
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
servers:
- url: https://{cluster}/apis/extensions.istio.io/v1alpha1
  description: Kubernetes API server endpoint for Istio Extensions v1alpha1
  variables:
    cluster:
      default: kubernetes.default.svc
      description: Kubernetes API server hostname
tags:
- name: RequestAuthentication
  description: JWT-based request authentication policies
  externalDocs:
    url: https://istio.io/latest/docs/reference/config/security/request_authentication/
paths:
  /namespaces/{namespace}/requestauthentications:
    get:
      operationId: listRequestAuthentications
      summary: Istio List RequestAuthentications
      description: List all RequestAuthentication resources in the specified namespace. A RequestAuthentication defines the request authentication methods supported by a workload. It will reject requests with invalid authentication information based on configured JWT rules.
      tags:
      - RequestAuthentication
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/labelSelector'
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/continue'
      responses:
        '200':
          description: Successful response containing list of RequestAuthentications
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RequestAuthenticationList'
        '401':
          description: Unauthorized
    post:
      operationId: createRequestAuthentication
      summary: Istio Create a RequestAuthentication
      description: Create a new RequestAuthentication resource in the specified namespace.
      tags:
      - RequestAuthentication
      parameters:
      - $ref: '#/components/parameters/namespace'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RequestAuthentication'
      responses:
        '201':
          description: RequestAuthentication created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RequestAuthentication'
        '401':
          description: Unauthorized
        '409':
          description: Conflict
  /namespaces/{namespace}/requestauthentications/{name}:
    get:
      operationId: getRequestAuthentication
      summary: Istio Get a RequestAuthentication
      description: Read the specified RequestAuthentication resource.
      tags:
      - RequestAuthentication
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/name'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RequestAuthentication'
        '401':
          description: Unauthorized
        '404':
          description: Not found
    put:
      operationId: replaceRequestAuthentication
      summary: Istio Replace a RequestAuthentication
      description: Replace the specified RequestAuthentication resource.
      tags:
      - RequestAuthentication
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/name'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RequestAuthentication'
      responses:
        '200':
          description: RequestAuthentication replaced
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RequestAuthentication'
        '401':
          description: Unauthorized
        '404':
          description: Not found
    delete:
      operationId: deleteRequestAuthentication
      summary: Istio Delete a RequestAuthentication
      description: Delete the specified RequestAuthentication resource.
      tags:
      - RequestAuthentication
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/name'
      responses:
        '200':
          description: RequestAuthentication deleted
        '401':
          description: Unauthorized
        '404':
          description: Not found
components:
  parameters:
    labelSelector:
      name: labelSelector
      in: query
      description: A selector to restrict the list of returned objects by their labels
      schema:
        type: string
    continue:
      name: continue
      in: query
      description: Continue token for paginated list requests
      schema:
        type: string
    name:
      name: name
      in: path
      required: true
      description: The resource name
      schema:
        type: string
    namespace:
      name: namespace
      in: path
      required: true
      description: The Kubernetes namespace
      schema:
        type: string
    limit:
      name: limit
      in: query
      description: Maximum number of resources to return
      schema:
        type: integer
  schemas:
    RequestAuthenticationList:
      type: object
      properties:
        apiVersion:
          type: string
        kind:
          type: string
          enum:
          - RequestAuthenticationList
        metadata:
          $ref: '#/components/schemas/ListMeta'
        items:
          type: array
          items:
            $ref: '#/components/schemas/RequestAuthentication'
    RequestAuthentication:
      type: object
      properties:
        apiVersion:
          type: string
          enum:
          - security.istio.io/v1
        kind:
          type: string
          enum:
          - RequestAuthentication
        metadata:
          $ref: '#/components/schemas/ObjectMeta'
        spec:
          type: object
          properties:
            selector:
              type: object
              properties:
                matchLabels:
                  type: object
                  additionalProperties:
                    type: string
              description: Workload selector to apply the policy to specific workloads.
            jwtRules:
              type: array
              items:
                type: object
                properties:
                  issuer:
                    type: string
                    description: Identifies the issuer that issued the JWT. The issuer claim (iss) in the JWT token must match this value.
                  audiences:
                    type: array
                    items:
                      type: string
                    description: The list of JWT audiences. The JWT aud claim must match at least one of the specified audiences.
                  jwksUri:
                    type: string
                    description: URL of the provider's public key set to validate the JWT signature.
                  jwks:
                    type: string
                    description: JSON Web Key Set of public keys to validate the JWT signature (inline).
                  fromHeaders:
                    type: array
                    items:
                      type: object
                      properties:
                        name:
                          type: string
                        prefix:
                          type: string
                    description: Headers to extract the JWT token from.
                  fromParams:
                    type: array
                    items:
                      type: string
                    description: Query parameters to extract the JWT token from.
                  outputPayloadToHeader:
                    type: string
                    description: Header name to output the validated JWT payload.
                  forwardOriginalToken:
                    type: boolean
                    description: Whether to forward the original JWT token to the upstream.
                  outputClaimToHeaders:
                    type: array
                    items:
                      type: object
                      properties:
                        header:
                          type: string
                        claim:
                          type: string
                    description: Claims to extract from the JWT and output as headers.
              description: List of rules that define the authentication requirements for incoming requests.
            targetRefs:
              type: array
              items:
                type: object
                properties:
                  kind:
                    type: string
                  group:
                    type: string
                  name:
                    type: string
              description: References to the target resources.
    ObjectMeta:
      type: object
      properties:
        name:
          type: string
          description: Name of the resource
        namespace:
          type: string
          description: Namespace of the resource
        labels:
          type: object
          additionalProperties:
            type: string
        annotations:
          type: object
          additionalProperties:
            type: string
        creationTimestamp:
          type: string
          format: date-time
        resourceVersion:
          type: string
    ListMeta:
      type: object
      properties:
        resourceVersion:
          type: string
        continue:
          type: string
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Kubernetes API server bearer token authentication
externalDocs:
  description: Istio Extensions Configuration Reference
  url: https://istio.io/latest/docs/reference/config/