For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.
TLS handshake timeout
Set a timeout for TLS handshake completion to protect the gateway from clients that open connections but never finish the handshake.
About the TLS handshake timeout
After a client opens a TCP connection to the gateway, the TLS handshake must complete before the connection can carry application traffic. If a client opens a connection and never finishes the handshake, the gateway keeps the connection open indefinitely, which consumes compute resources. To set a deadline for the handshake completion, set the transportSocketConnectTimeout field in a ListenerPolicy resource. If the timeout is reached, Envoy closes the connection. The timeout applies to every filter chain on the matched listener.
Before you begin
-
Follow the Get started guide to install kgateway.
-
Follow the Sample app guide to create a gateway proxy with an HTTP listener and deploy the httpbin sample app.
-
Get the external address of the gateway and save it in an environment variable.
export INGRESS_GW_ADDRESS=$(kubectl get svc -n kgateway-system http -o jsonpath="{.status.loadBalancer.ingress[0]['hostname','ip']}") echo $INGRESS_GW_ADDRESS
Set up the TLS handshake timeout
-
Create a ListenerPolicy with your TLS handshake timeout. In this example, you set a 10-second deadline for clients to complete the TLS handshake.
kubectl apply -f- <<EOF apiVersion: gateway.kgateway.dev/v1alpha1 kind: ListenerPolicy metadata: name: tls-handshake-timeout namespace: kgateway-system spec: targetRefs: - group: gateway.networking.k8s.io kind: Gateway name: http default: transportSocketConnectTimeout: 10s EOF -
Port-forward the gateway proxy and query the config dump to verify that
transport_socket_connect_timeoutis set on every filter chain.kubectl port-forward deployment/http -n kgateway-system 19000:19000 & PF_PID=$! sleep 2 curl -s 127.0.0.1:19000/config_dump | \ jq '.configs[] | select(.["@type"] == "type.googleapis.com/envoy.admin.v3.ListenersConfigDump") | .dynamic_listeners[].active_state.listener | select(.name | startswith("listener~")) | {name, filter_chains: [.filter_chains[] | {transport_socket_connect_timeout}]}' kill $PF_PIDExample output:
{ "name": "listener~8080", "filter_chains": [ { "transport_socket_connect_timeout": "10s" } ] }
Cleanup
You can remove the resources that you created in this guide.kubectl delete listenerpolicy tls-handshake-timeout -n kgateway-system