Skip to main content

Module filter

Module filter 

Source
Expand description

[admin.filter]: who may reach the admin listener at all.

The same policy engine as the ACME listener’s [filter] — named checks, ordered rules, trusted_proxies — built from its own section and evaluated at the connection stage only, on every request this listener serves, /health included. It exists for the deployment that cannot put a host firewall in front of the port (a container runtime owns the host’s netfilter tables), and it is not a substitute for one where one is available: a refused request here has still completed a TCP and, with admin.tls on, a TLS handshake.

§Connection stage only

Nothing on this listener ever names an identifier, so a rule that can only decide at the identifier stage would never run — a rule the operator believes in and the server ignores. build refuses one by name, and refuses the check types that have no meaning without an ACME order (identifiers, eab, ipam) before the engine gets to phrase the refusal in profile terms.

§The client address

ClientIp goes into the request extensions on every request, whether or not a rule is configured, and AdminClientIp prefers it to the socket peer. That is what lets admin.filter.trusted_proxies fix the login limiter behind a reverse proxy: without it every failed login counts against the proxy’s address.

No #[instrument] here, for the reason middlewares::filter gives: the client_ip record must land on the request span itself.

Functions§

admin_filter_middleware
Resolves the client address and runs the connection stage.
build
Builds the admin listener’s policy from admin.filter, refusing anything that could not decide here.