ABCDEFG
1
Issue #DescriptionReferencesComments
2
49Better modeling of a "virtual host" kind/featurestructure of API resources
3
95TLS: Align APIs with Personas #95structure of API resources
4
103Allow creation of domain names and TLS information without interacting with cluster operator #103structure of API resources
5
102Allow delegation of parts of a HTTP domain name's request space #102structure of API resourcesDelegation/Inclusion
6
TLS: expose an application over HTTPSfeature; must be able to specify HTTPS applicationself-service for TLS for developer
7
90Address SNI binding and bypass for TLS listeners kind/featurefeature; pin certificates to SNI name
8
9
Insecure Connection Policy kind/feature kind/user-storyfeature; upstream connection TLS
10
124TLS: Add Support for Gateway Reencryption #124feature; upstream connection TLSdupe of 52
11
52TLS Termination Policy #52feature; termination and upstream
12
91TLS: require client certificate verification for an application #91client certification validation (mTLS)
13
92TLS: require specific TLS version or other configuration for an application #92TLS protocol propertiesTLS version, ciphersuite
14
15
94xTLS: accept a TLS session and forward to a TCP endpoint #94TLS proxy duplicate?see #96, #123
16
17
Spec requirements on certificate secrets kind/featurefeature; properties of secrets
18
105xTLS: Store TLS cert-key secrets in a dedicated namespaces #105Protecting secrets via namespaces
19
20
TLS: enforce validation policy for an application kind/feature kind/user-storyPolicy over specifics of TLS configuration; valid TLS configuration see #92maybe out of scope; use OPA gateway?
21
22
114Pluggable access control #114Enable plugging of custom access control to terminationThis might be just for custom extension for now