Expand description
[admin.filter]: who may reach the admin listener at all.
The same policy engine as the ACME listener’s [filter] — named checks,
ordered rules, trusted_proxies — built from its own section and evaluated
at the connection stage only, on every request this listener serves,
/health included. It exists for the deployment that cannot put a host
firewall in front of the port (a container runtime owns the host’s
netfilter tables), and it is not a substitute for one where one is
available: a refused request here has still completed a TCP and, with
admin.tls on, a TLS handshake.
§Connection stage only
Nothing on this listener ever names an identifier, so a rule that can only
decide at the identifier stage would never run — a rule the operator
believes in and the server ignores. build refuses one by name, and
refuses the check types that have no meaning without an ACME order
(identifiers, eab, ipam) before the engine gets to phrase the
refusal in profile terms.
§The client address
ClientIp goes into the request extensions on every request, whether or
not a rule is configured, and AdminClientIp
prefers it to the socket peer. That is what lets
admin.filter.trusted_proxies fix the login limiter behind a reverse proxy:
without it every failed login counts against the proxy’s address.
No #[instrument] here, for the reason middlewares::filter gives: the
client_ip record must land on the request span itself.
Functions§
- admin_
filter_ middleware - Resolves the client address and runs the connection stage.
- build
- Builds the admin listener’s policy from
admin.filter, refusing anything that could not decide here.