curl -v https://<server>/httpbin/get?show_env=1 -H "X-Forwarded-For: 10.85.66.18"
"X-Forwarded-For": "10.85.66.18, 172.17.0.1, 152.16.191.116",
I'm looking into how Kong handles the X-Forwarded-For header and its impact on hardware load balancers, like F5. I saw that 0.11.0rc1 has a new configuration, trusted_ips, which is supposed to control who can be trusted as providers of X-Forwarded-For.
...
A couple of questions:1. With an empty trusted_ips configuration, shouldn't Kong have ignored the incoming X-Forwarded-For header?
2. How did Kong figured out there was another bridge, in this case Docker, in front of it? It makes sense, but what is the general logic here?