envoyproxy/gateway

Fix conformance for GatewayHTTPSListenerDetectMisdirectedRequests

Open

#5,879 opened on May 1, 2025

 (14 comments) (2 reactions) (1 assignee)Go (802 forks)auto 404
area/envoyhelp wanted

Repository metrics

Stars
 (2,871 stars)
PR merge metrics
 (PR metrics pending)

Description

We should return 421 when http/2 connection coalescing is detected

one workaround for now, is to disable http/2 ALPN when overlapping hostnames are detected, with the OverlappingTLSConfig condition added to the listeners https://gateway-api.sigs.k8s.io/geps/gep-3567/

I might be technically not deep enough into this https://gateway-api.sigs.k8s.io/geps/gep-3567/ states an option b of returning 421 for this. Is there a reason that envoy gateway is doing that which i am missing and/or could this be tracked as a followup in this or a new issue? Ideally it would be nice to not break http2 support like this :)

Originally posted by @MTRNord in #2675

Contributor guide