3 # Controls if sidecar is injected at the front of the container list and blocks the start of the other containers until the proxy is ready
4 holdApplicationUntilProxyStarts: true
6 # level: "default:debug"
8 rootNamespace: istio-config
12 service: oauth2-proxy.default.svc.cluster.local
15 includeHeadersInCheck: ["authorization", "cookie"]
16 headersToUpstreamOnAllow: ["x-forwarded-access-token", "authorization", "path", "x-auth-request-user", "x-auth-request-email", "x-auth-request-access-token"]
17 headersToDownstreamOnDeny: ["content-type", "set-cookie"]