How to debug Istio Authorization Policy?

Viewed 537

It is not very straightforward to test AuthorizationPolicy CRD as per https://istio.io/latest/docs/reference/config/security/authorization-policy/#AuthorizationPolicy-Action. I want to make sure that the AuthorizationPolicy I wrote can ALLOW the requests I want to allow, and DENY those I don't. But there are multiple hops of workloads in my cluster, so when the request failed, I have no idea where to look at for debugging the authorization rules.

Previous Research

I found this Debugging Authorization article but it was for IstioIdle 1.0. But I am using Istio 1.9, there are some differences in terms of istio architecture.

Edit

I have a Kubeflow app deployment guide which has old authorization policy (see ClusterRbacConfig in this). I want to preserve the original role-based access control policy, but use the new AuthorizatonPolicy CRD to achieve it.

0 Answers
Related