Skip to content

reverse_tunnel: add per-node connection cap with tenant-aware enforcement#45530

Draft
aakugan wants to merge 1 commit into
envoyproxy:mainfrom
aakugan:rc/rate-limit
Draft

reverse_tunnel: add per-node connection cap with tenant-aware enforcement#45530
aakugan wants to merge 1 commit into
envoyproxy:mainfrom
aakugan:rc/rate-limit

Conversation

@aakugan

@aakugan aakugan commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Commit Message

reverse_tunnel: add per-node connection cap with tenant-aware enforcement

Description

Add a configurable reverse tunnel connection cap via max_connections_per_node to protect workers from excessive accepted reverse connections. Enforce the cap in handshake validation using live upstream socket-manager counts, with tenant-aware scoping when tenant isolation is enabled.

Testing

Unit and integ tests which exercise and dont exercise the functionality.

…ment

Signed-off-by: aakugan <aakashganapathy2@gmail.com>
@aakugan aakugan marked this pull request as draft June 9, 2026 18:39
@repokitteh-read-only

Copy link
Copy Markdown

CC @envoyproxy/api-shepherds: Your approval is needed for changes made to (api/envoy/|docs/root/api-docs/).
envoyproxy/api-shepherds assignee is @wbpcode
CC @envoyproxy/api-watchers: FYI only for changes made to (api/envoy/|docs/root/api-docs/).

🐱

Caused by: #45530 was opened by aakugan.

see: more, trace.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants