test(mtls): add e2e tests for mTLS client cert identity forwarding

Tests verify: mTLS proxy works with valid client cert, mTLS rejects
connections without client cert, HTTP auth plugin receives client_cn,
client_san, client_cert_fingerprint via PeerCert context propagation.
This commit is contained in:
ginuerzh
2026-07-04 19:00:44 +08:00
parent eb9dbb1807
commit dd56308b2e
3 changed files with 333 additions and 0 deletions
+17
View File
@@ -0,0 +1,17 @@
services:
- name: https-mtls
addr: :8443
handler:
type: http
auther: auther-0
listener:
type: tls
tls:
certFile: /certs/server.pem
keyFile: /certs/server-key.pem
caFile: /certs/ca.pem
authers:
- name: auther-0
plugin:
type: http
addr: http://{{.ServerAddr}}:9000/auth