peer_identity_trust
Validates that the downstream mTLS peer identity matches a configured trusted peer before allowing the request to continue.
On this page
Validates that the downstream mTLS peer identity matches a configured trusted peer before allowing the request to continue.
Requires Cargo feature: spiffe.
Configuration Notes
Requests without a verified peer identity are rejected with 403. Requests with a peer identity that does not match any trusted peer entry are also rejected with 403.
Each trusted peer entry specifies one or more match fields. All configured fields on an entry must match the peer identity for that entry to accept the request.
SPIFFE identity is authorized earlier, at the mutual-TLS handshake (RequireNamed listener mode), so it is not a match field here. cert_digest and serial_number pin a specific certificate; organization is useful for bootstrap and controlled tests.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
trusted_peers | TrustedPeerConfig[] | yes | Trusted peer entries. |
trusted_peers[].cert_digest | string | no | Lowercase hex-encoded SHA-256 certificate digest. |
trusted_peers[].organization | string | no | X.509 subject organization (O= field). Weaker than certificate digest — useful for bootstrap and controlled test configurations where cert digests are not known ahead of time. |
trusted_peers[].serial_number | string | no | Certificate serial number. |
Example
filter: peer_identity_trust
trusted_peers:
- cert_digest: "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
- cert_digest: "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
organization: example-org