It is not very straightforward to test AuthorizationPolicy CRD as per https://istio.io/latest/docs/reference/config/security/authorization-policy/#AuthorizationPolicy-Action. I want to make sure that the AuthorizationPolicy I wrote can ALLOW the requests I want to allow, and DENY those I don't. But there are multiple hops of workloads in my cluster, so when the request failed, I have no idea where to look at for debugging the authorization rules.
Previous Research
I found this Debugging Authorization article but it was for IstioIdle 1.0. But I am using Istio 1.9, there are some differences in terms of istio architecture.
Edit
I have a Kubeflow app deployment guide which has old authorization policy (see ClusterRbacConfig in this). I want to preserve the original role-based access control policy, but use the new AuthorizatonPolicy CRD to achieve it.