Skip to content

docs: updated ssl sni parameter requirement in admin API#9176

Merged
juzhiyuan merged 1 commit into
apache:masterfrom
kayx23:master
Apr 6, 2023
Merged

docs: updated ssl sni parameter requirement in admin API#9176
juzhiyuan merged 1 commit into
apache:masterfrom
kayx23:master

Conversation

@kayx23

@kayx23 kayx23 commented Mar 27, 2023

Copy link
Copy Markdown
Member

SNI is only a required parameter iff type is server, meaning the SSL object is used in a downstream communication between APISIX and user, where APISIX acts as the server.

["if"] = {
properties = {
type = {
enum = {"server"},
},
},
},
["then"] = {
oneOf = {
{required = {"sni", "key", "cert"}},
{required = {"snis", "key", "cert"}}
}
},
["else"] = {required = {"key", "cert"}}
}

@kayx23

kayx23 commented Mar 30, 2023

Copy link
Copy Markdown
Member Author

Discussed with @kingluo to understand how SNI works for downstream and upstream segment of traffic a few days ago. Only to find out the doc isn't that accurate so I'm making a small edit but closing a large understanding gap...

@SkyeYoung
SkyeYoung requested a review from kingluo March 31, 2023 11:46
@juzhiyuan
juzhiyuan merged commit 59b6e76 into apache:master Apr 6, 2023
hongbinhsu added a commit to fitphp/apix that referenced this pull request Apr 11, 2023
* upstream/master: (25 commits)
  fix: upgrade lua-resty-ldap to 0.2.2 (apache#9254)
  feat(cli): support bypassing Admin API Auth by configuration (apache#9147)
  fix(ci): write version into xds first (apache#9274)
  fix: skip warning log when apisix.data_encryption.enable is false (apache#9057)
  docs: add-api7-information (apache#9260)
  docs: Fixed typo (apache#9244)
  docs: clarify what is client.ca in client-to-apisix-mtls.md (apache#9221)
  docs: Corrected typos and grammatical errors (apache#9216)
  docs: updated ssl sni parameter requirement in admin-api.md (apache#9176)
  fix: check upstream reference in traffic-split plugin when delete upstream (apache#9044)
  docs: Update proxy-rewrite headers.add docs (apache#9220)
  feat: suppot header injection for fault-injection plugin (apache#9039)
  fix: upgrade lua-resty-etcd to 1.10.4 (apache#9235)
  docs: fix incorrect semantic.yml link (apache#9231)
  feat: Upstream status report (apache#9151)
  fix: host_hdr should not be false (apache#9150)
  docs: remove APISIX base instruction (apache#9117)
  fix(cli): prevent non-`127.0.0.0/24` to access admin api with empty admin_key (apache#9146)
  docs: fix 404 link (apache#9160)
  fix(cors): consider using `allow_origins_by_regex` only when it is not `nil` (apache#9028)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants