Skip to content

Hold async admission requests and add RLS rate-limit example - #1

Merged
dio merged 5 commits into
mainfrom
ratelimit-admission
Oct 9, 2026
Merged

dio merged 5 commits into
mainfrom
ratelimit-admission

Conversation

@dio

@dio dio commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Header-only asynchronous admission could release a POST to the router when body data or trailers arrived before the callout decision. Hold both until admission completes, with regression coverage for forwarding and denial.

Add a reusable RLS v3 admission example with immutable policy snapshots, trusted descriptor sources, bounded Envoy-managed gRPC callouts, and explicit failure modes. Include a native-filter comparison and Fraser adoption boundaries. CI runs the new unit and Envoy e2e suites.

Validation:

  • Root race tests, rate-limit race tests, and all example unit packages pass.
  • Root Envoy e2e and rate-limit Envoy e2e pass after building their shared libraries.
  • Format checks, vet, and lint across all four modules pass. Lint requires the repository-pinned Go 1.26.4; the locally installed Go 1.27.1 is incompatible with the pinned linter.
  • A direct all-examples run could not complete unrelated e2e packages because their shared-library artifacts were missing or unavailable on the configured search path.

Local Envoy is pinned commit 0d6e3c60aa55 (1.39.0-dev). Envoy 1.38 qualification, Composer coexistence, and Fraser deployment are not established by these tests.

@dio
dio merged commit e7aec6c into main Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant