← Policy catalog
</> RequestAuthentication · Apache-2.0

JWT Audience Validation

requestauthentication-workload-jwt-audience

productIstio

Validate JWT issuer and required audience for the api-gateway workload.

What this is

A reference manifest to copy and adapt, not a rule cenroq enforces for you. It carries no severity, belongs to no bundle, and nothing on your cluster changes until you apply it yourself.

Manifest

apiVersion: security.istio.io/v1
kind: RequestAuthentication
metadata:
  name: jwt-audience
  namespace: default
  annotations:
    cenroq.io/displayName: "JWT Audience Validation"
    cenroq.io/description: "Validate JWT issuer and required audience for the api-gateway workload."
spec:
  selector:
    matchLabels:
      app: api-gateway
  jwtRules:
  - issuer: "https://issuer.example.com"
    audiences:
    - "api"
    jwks: |
      {"keys":[{"kty":"RSA","alg":"RS256","use":"sig","kid":"test-key-1","n":"l_ptJ-F--JPERDGfP08z6_Qx2nt9a3fWjYiDRI3ZGSjjnYfLFfcktla7iBkYfO2fgo2T_qQj1rk_pOQQEhEtoG0EzJo0VRq-M_YtYuvQkRzBd8BKYHH4wu2Pr31li5Izf5zSLD_8712kRmOHcy0eEIDuXFF6EC5aoosROLXDYu4eZRybFQQSBuwdZD4qruQ7FNb-NrAuMLkV5tjkeGab1bJdNqTuSYt8ZOrD900swPub4w_2zEqvfJjl3FbpWxQX4rkRcI8TK7lc2AeOX6tWJwlRqkBMv_FsEtmYcKz31yjWPyUehgHsYCF6SbDRDdhz5SRaRyon-wBnQiT5-93JKw","e":"AQAB"}]}

Save it as requestauthentication-workload-jwt-audience.yaml — the commands below assume that name.

Apply it

This is a manifest, not an admission policy, so there is nothing for kubeapt validate to check it against. Adapt the selectors and namespace first, then:

$ kubectl apply -f ./requestauthentication-workload-jwt-audience.yaml