Skip to content

Conversation

@salonichf5
Copy link
Contributor

Proposed changes

Updates existing secure traffic guide to showcase mutual TLS connection between Gateway and Backends.

Checklist

Before sharing this pull request, I completed the following checklist:

Footnotes

  1. Potentially sensitive information includes personally identify information (PII), authentication credentials, and live URLs. Refer to the style guide for guidance about placeholder content.

@salonichf5 salonichf5 requested a review from a team as a code owner November 25, 2025 22:57
@github-actions github-actions bot added documentation Improvements or additions to documentation product/ngf Issues related to NGINX Gateway Fabric labels Nov 25, 2025
@salonichf5 salonichf5 requested a review from a team November 25, 2025 22:57
@salonichf5
Copy link
Contributor Author

Screenshot 2025-11-25 at 3 41 38 PM

Incase preview doesn't work

Copy link
Member

@ADubhlaoich ADubhlaoich left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Please ensure the merge message adheres to Conventional Commits.

Copy link
Contributor

@bjee19 bjee19 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we want to overwrite the tls section and make this document purely an mtls document? If a user wants to only have tls, and doesn't need mtls wouldn't they not be able to follow this document?

@salonichf5
Copy link
Contributor Author

Do we want to overwrite the tls section and make this document purely an mtls document? If a user wants to only have tls, and doesn't need mtls wouldn't they not be able to follow this document?

The original goal was to extend this document to also demonstrate mTLS between the Gateway and the upstream. I think the current scope still makes sense, because the security posture is ultimately driven by the application configuration, which is owned by the user.

In this setup, the secure-app configuration determines whether we need Gateway TLS and a BackendTLSPolicy. We assume the user understands the characteristics of the application they’re exposing and, based on that, can decide what guarantees the Gateway must provide for successful communication with the backend.

@salonichf5 salonichf5 requested a review from bjee19 December 3, 2025 18:07
@salonichf5 salonichf5 merged commit dd700aa into nginx:ngf-release-2.3 Dec 3, 2025
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation product/ngf Issues related to NGINX Gateway Fabric

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants