{ Community }
  • Academy
  • Docs
  • Developers
  • Resources
    • Community Articles
    • Apigee on GitHub
    • Code Samples
    • Videos & eBooks
    • Accelerator Methodology
  • Support
  • Ask a Question
  • Spaces
    • Product Announcements
    • General
    • Edge/API Management
    • Developer Portal (Drupal-based)
    • Developer Portal (Integrated)
    • API Design
    • APIM on Istio
    • Extensions
    • Business of APIs
    • Academy/Certification
    • Adapter for Envoy
    • Analytics
    • Events
    • Hybrid
    • Integration (AWS, PCF, Etc.)
    • Microgateway
    • Monetization
    • Private Cloud Deployment
    • 日本語コミュニティ
    • Insights
    • IoT Apigee Link
    • BaaS/Usergrid
    • BaaS Transition/Migration
    • Apigee-127
    • New Customers
    • Topics
    • Questions
    • Articles
    • Ideas
    • Leaderboard
    • Badges
  • Log in
  • Sign up

Get answers, ideas, and support from the Apigee Community

  • Home /
  • Adapter for Envoy /
This question was closed Oct 07, 2020 at 11:45 PM by Vitalii Burak.
avatar image
0
Question by Vitalii Burak · Oct 07, 2020 at 11:40 PM · 50 Views rbacdeny

Authenticate success but "RBAC: access denied"

We use apigee-envoy-adapter 1.0.0 and when we try to hit the service we got:

curl -i http://example-dev2.eus1-devqa.xxx.com/example/v1/items -H "x-api-key: xxx"
HTTP/1.1 403 Forbidden
content-length: 19
content-type: text/plain
date: Wed, 07 Oct 2020 23:29:32 GMT
server: istio-envoy
x-envoy-upstream-service-time: 8
RBAC: access denied%

in apigee-remote-service-envoy logs we see that Authenticate success but still PERMISSION_DENIED:

DEBUG auth/auth.go:98 Authenticate: key: YJNo1..., claims: map[string]interface {}(nil)<br />DEBUG auth/auth.go:125 using api key from request<br />DEBUG auth/auth.go:157 Authenticate success: &auth.Context{Context:(*server.Handler)(0xc0000b2600), ClientID:"YJNo1...", AccessToken:"", Application:"example-ms", APIProducts:[]string{"remote-service"}, Expires:time.Time{wall:0x0, ext:63737710469, loc:(*time.Location)(0x15ab960)}, DeveloperEmail:"xxx", Scopes:[]string{""}, APIKey:"YJNo1..."}<br />DEBUG product/manager.go:246<br />Resolve api: example-dev2.eus1-devqa.xxx.com, path: /example/v1/items, scopes: []<br />Selected: []<br />Eliminated: [remote-service doesn't exist]<br />DEBUG server/authorization.go:225 sending ok (actual: PERMISSION_DENIED)

On Apigee side we see that requests are passing fine

Could you please suggest what could be misconfigured?

Comment
Add comment
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

Close

0 Answers

  • Sort: 

Follow this Question

Answers Answers and Comments

38 People are following this question.

avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image

Related Questions

Authenticate success but "RBAC: access denied" 0 Answers

Authenticate success but "RBAC: access denied" 0 Answers

Authenticate success but "RBAC: access denied" 0 Answers

  • Products
    • Edge - APIs
    • Insights - Big Data
    • Plans
  • Developers
    • Overview
    • Documentation
  • Resources
    • Overview
    • Blog
    • Apigee Institute
    • Academy
    • Documentation
  • Company
    • Overview
    • Press
    • Customers
    • Partners
    • Team
    • Events
    • Careers
    • Contact Us
  • Support
    • Support Overview
    • Documentation
    • Status
    • Edge Support Portal
    • Privacy Policy
    • Terms & Conditions
© 2021 Apigee Corp. All rights reserved. - Apigee Community Terms of Use - Powered by AnswerHub
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Create an article
  • Post an idea
  • Spaces
  • Product Announcements
  • General
  • Edge/API Management
  • Developer Portal (Drupal-based)
  • Developer Portal (Integrated)
  • API Design
  • APIM on Istio
  • Extensions
  • Business of APIs
  • Academy/Certification
  • Adapter for Envoy
  • Analytics
  • Events
  • Hybrid
  • Integration (AWS, PCF, Etc.)
  • Microgateway
  • Monetization
  • Private Cloud Deployment
  • 日本語コミュニティ
  • Insights
  • IoT Apigee Link
  • BaaS/Usergrid
  • BaaS Transition/Migration
  • Apigee-127
  • New Customers
  • Explore
  • Topics
  • Questions
  • Articles
  • Ideas
  • Badges