No Permissive Authz
istio.no-permissive-authz
Fails when an AuthorizationPolicy grants blanket access — an ALLOW action with a rule that has no from/to/when constraints (matches every source). Accidental allow-all rules quietly negate the rest of the mesh's authz.
Compatible Integrations
This guardrail works with the following integrations. Click to see how to use No Permissive Authz with each collector.
Enable This Guardrail
Add the parent policy to your lunar-config.yml to enable this guardrail.
policies:
- uses: github://earthly/lunar-lib/policies/istio@v1.0.5
include: [no-permissive-authz]
# with: ...
How This Guardrail Works
This guardrail is part of the Istio Guardrails policy. It evaluates data collected by integrations and produces a pass/fail check with actionable feedback.
When enabled, this check runs automatically on every PR and in AI coding workflows, providing real-time enforcement of your engineering standards.
Learn How Lunar Works →Configuration Options
These inputs can be configured in your lunar-config.yml to customize
how the parent policy (and this guardrail) behaves.
| Input | Required | Default | Description |
|---|---|---|---|
required_mtls_mode
|
Optional |
STRICT
|
Required mesh-wide mTLS mode for the mtls-strict check (STRICT or PERMISSIVE) |
approved_tls_versions
|
Required | — | Comma-separated TLS protocol versions, by Istio name (TLSV1_0, TLSV1_1, TLSV1_2, TLSV1_3), that tls-approved accepts. Every version a server or the mesh can negotiate must be listed. Empty (the default) skips the version half of the check. |
approved_cipher_suites
|
Required | — | Comma-separated cipher suites that tls-approved accepts (e.g. ECDHE-ECDSA-AES256-GCM-SHA384). Not required where the minimum version is TLS 1.3. Empty (the default) skips the cipher half of the check. |
Istio Guardrails
This guardrail is part of the Istio Guardrails policy, which includes 8 guardrails for deployment and infrastructure.
Ready to Automate Your Standards?
See how Lunar can turn your AGENTS.md, engineering wiki, compliance docs, or postmortem action items into automated guardrails with our 200+ built-in guardrails.