Videos xg1zNlzw7Jk
Claws Out: Securing and Building with OpenClaw - Nick Taylor, Pomerium
Scene timeline
57 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 193
- whisperx 193
- chunks
- 30
- from 193 cues
- keyframes
- 53
- kept of 57 captured
- frames with text
- 52
- 2,706 lines read
- chapters
- 0
- from the source metadata
- keyframe bytes
- 8.0 MB
- word timings on 193 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-11 03:38 | 1m 11s |
stt |
done | — | 2026-08-11 03:39 | 18s |
chunk |
done | — | 2026-08-11 03:39 | 0s |
text_embed |
done | — | 2026-08-11 03:39 | 0s |
keyframe |
done | — | 2026-08-11 03:39 | 1m 31s |
ocr |
done | — | 2026-08-11 03:41 | 52s |
frame_embed |
done | — | 2026-08-11 03:42 | 8s |
Frames, and what the machine read
-
- Al Engineer0.94
- EUROPE1.00
-
- PRESENTINGSPONSOR1.00
- Google DeepMind1.00
-
- PLATINUM SPONSORS0.98
- # Braintrust0.95
- WorkOS OpenAI0.95
-
- Claw1.00
- AlEngineer0.95
- WorkOs0.88
- AlEngineel0.93
- EUROPE1.00
- EUROPE1.00
- SAFE1.00
- AlEngineer0.98
- Braintrust1.00
- INTELLIGENCE1.00
- EUROPE1.00
- WE1.00
- arize1.00
- AlEngineer0.99
- EUROPE1.00
- AlEngineer0.99
- EUROPE1.00
- PRESENTED BY1.00
- AlEngineer0.98
- Trigger.dev1.00
- Google DeepMind0.99
- EUROPE1.00
- Modal1.00
- AlEngineer0.94
- EUROPE1.00
-
- AlEngineer0.95
- Wor0.83
- EUROPE1.00
- About Me0.99
- SAFE1.00
- AIEngin0.95
- INTELLIGENCE1.00
- EUROPE1.00
- Developer Advocate at Pomerium1.00
- WE1.00
- ODEN0.99
- From Montreal, Quebec, Canada0.99
- AlEngineer1.00
- GitHub Star, MS MVP, AWS Community Builder0.99
- EUROPE1.00
- @nickytonline pretty much everywhere1.00
- PRESENTED BY1.00
- AlEngin0.90
- Google DeepMind1.00
- EUROPE1.00
- M1.00
- 00□0.60
- Google DeepMind0.99
- AlEngineer0.98
- EUROPE1.00
-
- About Me0.99
- Goo0.98
- pMind0.99
- Developer Advocate at Pomerium0.99
- From Montreal, Quebec, Canada1.00
- GitHub Star, MS MVP, AWS Community Builder0.99
- WE1.00
- @nickytonline pretty much everywhere1.00
- OPEN1.00
- 00□0.59
- AlEngineer0.98
- #Braintrust0.97
- WorkOS1.00
- OpenAl0.93
- EUROPE1.00
-
- Go0.97
- epMind0.98
- WE1.00
- OPEN1.00
- AlEngineer0.97
- Braintrust1.00
- WorkOS1.00
- OpenAl0.94
- EUROPE1.00
-
- [Feature]: Allow disabling auth with LAN binding for reverse proxy0.99
- setups #15601.00
- Closed1.00
- #159400.95
- Go0.99
- epMind1.00
- nickytonline opened on Jan 24 - edited by nickytonline0.99
- Edits0.92
- Contributor1.00
- Summary1.00
- I'm trying to secure Clawdbot with Pomerium (an Identity Aware Proxy). Full disclosure, I work at Pomerium. The proxy handles0.98
- authentication, so Clawdbot doesn't need its own auth.0.99
- But when I bind to LAN, Clawdbot forces token authentication. This breaks WebSocket connections because browsers can't1.00
- pass the token in WebSocket message payloads. The web Ul loads but shows "disconnected (1008): unauthorized* for all real-0.98
- OPEN1.00
- time features.1.00
- Proposed solution1.00
- Allow gateway.auth: "off" when gateway.bind: "lan" for reverse proxy scenarios.0.99
- Could add an explicit opt-in flag like:0.99
- gateway: {1.00
- bind: "lan",0.98
- auth: {0.96
- mode: "off",0.99
- allowUnauthenticatedProxy: true1.00
- This would only work when users explicitly opt in and understand they need a reverse proxy handling auth.1.00
- Alternatives considered1.00
- Google DeepMind0.99
- AlEngineer0.96
- EUROPE1.00
-
- AlEngineer0.94
- Wor0.88
- EUROPE1.00
- [Feature]: Allow disabling auth with LAN binding for reverse proxy0.99
- setups #15601.00
- SAFL0.98
- AlEngil0.86
- © Closed0.89
- 1#159400.98
- INTELLIGENC0.99
- EUROP1.00
- nickytonline opened on Jan 24 - edited by nickytonline0.99
- Edits1.00
- Contributor0.98
- WE1.00
- Summary1.00
- ODEN0.99
- ar1.00
- I'm trying to secure Clawdbot with Pomerium (an Identity Aware Proxy). Full disclosure, I work at Pomerium. The proxy handles0.99
- AlEngineer1.00
- authentication, so Clawdbot doesn't need its own auth.0.99
- EUROPE1.00
- pass the token in WebSocket message payloads. The web Ul loads but shows "disconnected (1008): unauthorized* for all real-0.99
- But when I bind to LAN, Clawdbot forces token authentication. This breaks WebSocket connections because browsers can't1.00
- PRESENTED BY1.00
- AlEngi0.96
- time features.1.00
- Google DeepMind0.98
- EUROP1.00
- Proposed solution1.00
- Allow gateway.auth: "off" when gateway.bind: "lan" for reverse proxy scenarios.0.99
- Could add an explicit opt-in flag like:1.00
- M1.00
- 50.56
- gateway: {0.99
- bind: "lan",0.97
- auth: {0.96
- mode: "off",0.99
- allowUnauthenticatedProxy: true1.00
- This would only work when users explicitly opt in and understand they need a reverse proxy handling auth.0.99
- Alternatives considered1.00
- AlEngineer0.97
- Braintrust1.00
- WorkOS1.00
- OpenAl0.93
- EUROPE1.00
-
- AlEngineer0.94
- Google De0.98
- EUROPE1.00
- [Feature]: Allow disabling auth with LAN binding for reverse proxy0.99
- setups #15601.00
- runp1.00
- AIEngii0.83
- Closed0.93
- 1#159400.99
- EUROP1.00
- nickytonline opened on Jan 24 - edited by nickytonline0.99
- Edits0.94
- Contributor1.00
- WE1.00
- OPEN1.00
- Trigg1.00
- Summary1.00
- I'm trying to secure Clawdbot with Pomerium (an Identity Aware Proxy). ull disclosure, I work at Pomerium. The proxy handles0.98
- AlEngineer0.99
- authentication, so Clawdbot doesn't need its own auth.0.99
- EUROPE1.00
- pass the token in WebSocket message payloads. The web Ul loads but shows "disconnected (1008): unauthorized* for all real-0.99
- But when I bind to LAN, Clawdbot forces token authentication. This breaks WebSocket connections because browsers can't1.00
- PRESENTED BY1.00
- AlEngi0.95
- time features.1.00
- Google DeepMind1.00
- EUROP1.00
- Proposed solution1.00
- Allow gateway.auth: "off" when gateway.bind: "lan" for reverse proxy scenarios.0.99
- Could add an explicit opt-in flag like:0.98
- CLOI0.98
- gateway: {1.00
- bind: "lan",0.98
- auth: {0.96
- mode: "off",1.00
- allowUnauthenticatedProxy: true1.00
- This would only work when users explicitly opt in and understand they need a reverse proxy handling auth.0.99
- Alternatives considered1.00
- Google DeepMind1.00
- AlEngineer0.97
- EUROPE1.00
-
- OS0.86
- marcwestermann on Jan 241.00
- PEN0.73
- I'd be interested in this too - I have a Caddy setup via tailscale and the gateway crashes after a0.99
- couple of minutes when exposed via this. Thank you@nickytonline1.00
- Braintrust1.00
- WorkOSOpenAI0.95
- AlEngineer0.97
- EUROPE1.00
-
- steipete on Jan 240.97
- Contributor1.00
- kOS0.89
- Hi Nick - yes I'd love if you could work on this. Just needs to be explicit - I don't want folks to leave gates open until they really0.99
- know what they're doing.0.98
- Here some codex notes1.00
- WE1.00
- Findings1.00
- OPEN1.00
- • Critical: core runtime guard explicitly rejects non-loopback binds when auth mode is none; change would be a deliberate0.99
- sOi0.70
- security regression and needs a new explicit override + audit/docs updates. src/gateway/server-runtime-config.ts:770.99
- src/security/audit.ts:2041.00
- • High: "auth off" does not bypass Control UI device identity on insecure HTTP; without allowlnsecureAuth +0.99
- token/password, the Ul is still blocked before auth is even checked. src/gateway/server/ ws-connection/message-0.99
- handler.ts:3011.00
- • Medium: 1008 "unauthorized" is triggered by the WS connect auth path; any proxy-only auth still needs a server-side trust0.99
- mechanism (headers or mTLS), otherwise it fails here. src/gateway/server/ws-connection/message-handler.ts:4940.99
- Questions/assumptions1.00
- Engineering the future of Al0.97
- AlEngineer0.98
- EUROPE1.00
-
- Prior to trusted proxy auth mode1.00
- rkos0.79
- Even if secured by a proxy (nginx, Caddy, Pomerium etc.), still had to0.99
- paste in an auth token in the Ul for websocket connections1.00
- Still had to pair for any new device1.00
- WE1.00
- OPEN1.00
- Google DeepMind0.99
- AlEngineer0.98
- EUROPE1.00
-
- steipete on Feb 141.00
- Contributor1.00
- Great work and clean PR!1.00
- kOS0.85
- fix: harden trusted-proxy auth follow-ups1.00
- 279d4b31.00
- E0.65
- steipete force-pushed the feat/trusted-prexy-auth branch from 8d158ac to 279d4b3 2 months ago0.99
- Compare1.00
- OPEN1.00
- steipete merged commit 1fb52b4 into openclaw: main on Feb 140.99
- View details1.00
- Revert1.00
- 13 checks passed1.00
- steipete on Feb 140.97
- Contributor1.00
- ...0.57
- Merged via squash.1.00
- • Prepared head SHA: 279d4b30.97
- · Merge commit: 1fb52b40.96
- Thanks@nickytonline!0.99
- AlEngineer0.99
- Braintrust1.00
- WorkOS1.00
- OpenAl0.94
- EUROPE1.00
-
- a/.openclaw/openclaw.json1.00
- +++ b/.openclaw/openclaw.json0.99
- @a -1,10 +1,17 @a0.90
- antrust0.96
- "gateway": {0.98
- "bind": "loopback",0.97
- "bind": "lan"0.99
- "trustedProxies": ["10.0.0.1"],0.99
- "auth": {0.97
- WE1.00
- "mode": "token",0.99
- OPEN1.00
- "token": "3a7f2e9b4c1d8e6a5f2b9c4e7d1a3f81.00
- SOIP0.82
- b6e9c2d4a5f7b8e9d1c3a4f6e8b2d9a"1.00
- "mode": "trusted-proxy",1.00
- "trustedProxy": {0.99
- "userHeader": "x-pomerium-claim-email"1.00
- "requiredHeaders": {1.00
- "x-pomerium-jwt-assertion": true0.99
- Google DeepMind1.00
- AlEngineer0.98
- EUROPE1.00
-
- AlEngineer0.98
- Brair0.94
- EUROPE1.00
- a/.openclaw/openclaw.json1.00
- +++ b/.openclaw/openclaw.json1.00
- @@ -1,10 +1,17 @a0.90
- Tess1.00
- AlEngir0.94
- EUROPI0.97
- "gateway": {0.96
- "bind": "loopback",0.99
- WE1.00
- "bind": "lan"0.99
- ODEN0.98
- Sno0.82
- "trustedProxies": ["10.0.0.1"],1.00
- AlEngineer0.97
- "auth": {0.97
- EUROPE1.00
- "mode": "token",0.99
- PRESENTED BY1.00
- AlEngir0.89
- "token": "3a7f2e9b4c1d8e6a5f2b9c4e7d1a3f80.99
- Google DeepMind1.00
- EUROPI1.00
- b6e9c2d4a5f7b8e9d1c3a4f6e8b2d9a"1.00
- "mode": "trusted-proxy",0.98
- "trustedProxy": {0.98
- Sc0.67
- "userHeader": "x-pomerium-claim-email"1.00
- "requiredHeaders": {0.99
- "x-pomerium-jwt-assertion": true1.00
- AlEngineer0.98
- # Braintrust0.96
- WorkOS1.00
- OpenAl0.93
- EUROPE1.00
-
- AlEngineer0.96
- Brair0.95
- EUROPE1.00
- With trusted proxy auth mode0.99
- Tess1.00
- AlEngir0.92
- EUROPI0.91
- No more token for web socket connections1.00
- WE1.00
- ODEN0.96
- Snc0.86
- No longer need to pair devices0.99
- AlEngineer0.97
- EUROPE1.00
- PRESENTED BY1.00
- AlEngir0.92
- Google DeepMind1.00
- EUROPI1.00
- Sc0.89
- Google DeepMind0.99
- AlEngineer0.98
- EUROPE1.00
-
- AlEngineer0.96
- Brair0.95
- EUROPE1.00
- openclaw / openclaw0.96
- 十0.89
- Tess1.00
- AlEngir0.91
- Code1.00
- Issues 5k+0.98
- Pull requests 5k+1.00
- Agents1.00
- Actions1.00
- Security and quality1.00
- 4691.00
- Insights1.00
- EUROPI0.97
- [Bug]: Control Ul ignores gateway.auth.mode:1.00
- New issue0.87
- "trusted-proxy" and always uses device1.00
- https://github.com/openclaw/openclaw/pul/254280.99
- 出☆0.61
- 00.54
- Chat0.89
- WE1.00
- pairing #252931.00
- openclaw / openclaw0.97
- n0.92
- ODEN0.97
- Sno0.80
- ©Closed0.94
- B Locked0.89
- 1#254280.85
- <> Code0.96
- Issues 5k+0.98
- I] Pull requests 5k+0.94
- Agents0.97
- Actions0.97
- ① Security and quality0.96
- 4691.00
- Insights1.00
- AlEngineer0.97
- anthony-spruyt opened on Feb 241.00
- Code -0.89
- EUROPE1.00
- Summary1.00
- fix(gateway): allow trusted-proxy control-ui auth to skip device1.00
- Google DeepMind1.00
- PRESENTED BY1.00
- AlEngir0.93
- EUROPI1.00
- trusted-proxy mode is configured with a valid user header and trusted0.98
- Control UI WebSocket connections bypass the configured0.98
- gateway.auth.mode and always use device pairing auth, even when0.99
- pairing #254280.99
- proxy CIDR.0.96
- Merged1.00
- by steipete openclaw:main Sid-Qin:fix/control-ui-trusted-proxy-skip--0.96
- Steps to reproduce1.00
- 1. Configure gateway with rusted-proxy auth behind a reverse proxy0.97
- Conversation 20.98
- -- Commits 20.96
- Checks 251.00
- 3 Files changed 40.91
- +48-50.95
- Sc0.78
- that injects a user header:0.98
- Sid-Qin on Feb 24 - edited0.96
- Contributor1.00
- Reviewers1.00
- "gateway": {0.90
- "auth": {0.89
- "node": "trusted-proxy",0.97
- Summary1.00
- gateway1.00
- size:S0.98
- Describe the problem and fix in 2-5 bullets:1.00
- Development1.00
- • Problem: Control Ul pairing bypass only checked sharedAuthok, but trusted-0.98
- [Bug]: Control Ul ignores gatewa...0.98
- proxy auth sets sharedAuth0k=false — so trusted-proxy users were0.97
- incorrectly forced through device pairing.1.00
- Notifications1.00
- Customize1.00
- • Why it matters: Users connecting via a trusted proxy could not access the0.98
- Control Ul without completing an unnecessary and confusing pairing step.0.99
- None0.99
- All0.93
- Status0.94
- • What changed: src/gateway/server/ws-connection/connect-policy.ts and0.99
- message-handler.ts now recognize trusted-proxy auth as a valid reason to1.00
- 2 participants1.00
- skip device pairing, alongside shared auth.0.98
- A00.56
- Google DeepMind1.00
- AlEngineer0.97
- EUROPE0.99
-
- 出户☆0.52
- openclaw / openclaw0.95
- Q0.89
- n0.97
- Code0.99
- Issues 5k+0.99
- Pull requests 5k+0.97
- Agents1.00
- Actions1.00
- Security and quality1.00
- 4690.99
- Insights1.00
- rust1.00
- [Bug]: Control Ul ignores gateway.auth.mode:1.00
- New issue0.98
- "trusted-proxy" and always uses device1.00
- https:/github.com/openclaw/openclaw/pul/254280.97
- 出Q☆0.60
- Chat0.98
- pairing #252930.99
- openclaw / openclaw0.97
- n0.88
- 日0.80
- © Closed0.87
- Locked0.95
- #254280.94
- <> Code0.93
- Issues 5k+0.93
- Il Pull requests 5k+0.98
- Agents0.95
- Actions0.95
- ① Security and quality0.94
- 4691.00
- Insights1.00
- anthony-spruyt opened on Feb 240.98
- Code0.95
- Summary1.00
- fix(gateway): allow trusted-proxy control-ui auth to skip device1.00
- OPEN0.99
- Control UI WebSocket connections bypass the configured0.99
- gateway.auth.mode and always use device pairing auth, even when0.99
- pairing #254280.99
- trusted-proxy mode is configured with a valid user header and trusted1.00
- proxy CIDR.0.95
- Merged1.00
- by steipete openclaw:mainSid-Qin:fix/control-ui-trusted-proxy-skip--0.96
- Steps to reproduce1.00
- 1. Configure gateway with trusted-proxy auth behind a reverse proxy0.98
- Conversation 20.99
- -- Commits 20.91
- Checks 250.96
- Files changed 40.95
- +48-50.95
- that injects a user header:1.00
- {0.69
- "gatewny": {0.91
- Sid-Qin on Feb 24 - edited0.97
- Contributor1.00
- Reviewers1.00
- "auth": (0.91
- "node": "trusted-proxy",0.97
- Summary1.00
- gateway1.00
- size:S0.94
- Describe the problem and fix in 2-5 bullets:1.00
- Development1.00
- • Problem: Control UI pairing bypass only checked sharedAuth0k, but trusted-0.98
- [Bug]: Control UI ignores gatewa...0.97
- proxy auth sets sharedAuth0k=false - so trusted-proxy users were0.98
- incorrectly forced through device pairing.1.00
- Notifications1.00
- Customize1.00
- • Why it matters: Users connecting via a trusted proxy could not access the0.98
- Control Ul without completing an unnecessary and confusing pairing step.0.99
- None0.97
- All0.95
- Status1.00
- • What changed: src/gateway/server/ws-connection/connect-policy.ts and0.99
- message-handler. ts now recognize trusted-proxy auth as a valid reason to0.99
- 2 participants1.00
- skip device pairing, alongside shared auth.1.00
- Engineering the future of Al1.00
- AlEngineer0.97
- EUROPE1.00
-
- O0.64
- openclaw / openclaw0.97
- Code1.00
- Issues1.00
- 5k+1.00
- Pull requests0.99
- 5k+1.00
- Agents1.00
- Actions1.00
- More1.00
- New issue1.00
- 凸□0.54
- d1.00
- PEN0.81
- [Feature]: Allow disabling auth with LAN binding for reverse1.00
- proxy setups #15600.97
- Closed1.00
- 8#159400.95
- Google DeepMind1.00
- AlEngineer0.99
- EUROPE1.00
-
- N binding for reverse0.98
- openclaw / openclaw0.99
- AlEngineer0.99
- SOURCE0.99
- Code1.00
- Issues1.00
- 5k+1.00
- Pull requests0.96
- 5k+1.00
- Agents1.00
- Actions1.00
- More1.00
- Hn0.51
- Googl DeepMind0.94
- New issue0.99
- □0.65
- [Feature]: Allow disabling auth with LAN binding for reverse1.00
- proxy seups #15601.00
- Closed1.00
- 8#159400.94
- Google DeepMind1.00
- AlEngineer0.98
- EUROPE1.00
-
- AI0.94
- 三0.93
- openclaw / openclaw0.97
- Q1.00
- Code1.00
- Issues1.00
- 5k+1.00
- Pull requests0.96
- 5k+1.00
- Agents1.00
- Actions1.00
- More1.00
- WE1.00
- New issue0.97
- OPEN1.00
- [Feature]: Allow disabling auth with LAN binding for reverse1.00
- proxy seups #15600.99
- Closed1.00
- 80#159400.95
- AlEngineer0.98
- Braintrust1.00
- WorkOS1.00
- OpenAI0.92
- EUROPE1.00
-
- Oper1.00
- WE1.00
- d0.68
- ODEN0.96
- McClaw1.00
The page's on-screen-text budget of 600
lines is spent, so the last cards in this grid list fewer lines than they
hold. Narrow the page with ?frames= to read them.
Transcript
193 cues· 2,590 words· 13,222 chars
- 0:15 So, like Phil said, I work at Pomarium, and he's not the first person to have trouble pronouncing it, so I actually convinced the marketing team to create Pomeranian stickers, so if anybody wants Pomeranian stickers, I have a bunch with me.
- 0:31 A bit about me, I'm a dev advocate over at Pomarium, as Phil said.
- 0:35 I'm from Canada.
- 0:37 Halen from Montreal.
- 0:40 If anybody likes poutine and bagels, feel free to chat with me after.
- 0:44 Also a GitHub star, Microsoft MVP, and AWS Community Builder, and you can pretty much find me everywhere, at NickyTOnline.
- 0:55 I was pretty happy to see this, that there's a pretty sizable instance on-prem of OpenClaw, so I was pretty happy with that, and it looks like that's the operator there.
- 1:08 Cool.
- 1:09 So I don't know.
- 1:11 I came up with a funny title, I guess, but Claws Out.
- 1:14 We're going to talk about a feature I contributed to the Open Claw project back in February.
- 1:21 And it's about hardening access to the control plane.
- 1:24 So I'm assuming everybody here is running an Open Claw or Open Claw curious.
- 1:32 Is anybody running a mode called trusted proxy auth mode?
- 1:37 You might not be, but okay.
- 1:39 You might be on the, who's on the token auth?
- 1:41 Okay.
- 1:44 Anyways, so at Pomarium where I work, you know, I'm always just trying to secure things.
- 1:50 That's just part of what I do.
- 1:53 And I was able to secure Open Club, but it meant I still had to add a token for the WebSocket connection.
- 2:01 I had to always pair my device and stuff.
- 2:04 And you don't really need that with a trusted proxy, like specifically the one that I work on, which is OpenCore, it's called an identity-aware proxy.
- 2:14 So if anybody's ever used GCP, there's an IAP in there, it's called an identity-aware proxy, something that came out of Google.
- 2:22 Essentially, you've got an identity provider, a policy engine, and a reverse proxy, so those
- 2:28 It's not the lethal trifecta in the sense that you usually hear, but it's a pretty solid security approach for securing internal apps.
- 2:36 So I was like, of course, I kind of got annoyed that I had to add this token still and do the pairing every time.
- 2:44 I understood why they were there, but I just proposed this issue and then at least one other person who uses Caddy chimed in and said, hey, that sounds like a good idea.
- 2:57 And then Peter was like, yeah, let's work on this.
- 3:01 And he laid out the criteria that he wanted to have for this feature.
- 3:06 So I went ahead and worked on it.
- 3:09 And yeah, again, prior to trusted proxy auth mode, even if you were secured by a proxy, you still had to paste in that auth token in the UI for the WebSocket connection.
- 3:20 And also it sticks it in the query string, which obviously this is really more for just only local mode, really.
- 3:28 and still having to pair the device.
- 3:31 I don't know if people get annoyed by pairing the device, but I'd just be on my phone after I just set it up, and then I was like, I gotta go to the other thing to set it up.
- 3:41 Basically, you still had to do those things, even if it was secured with a proxy.
- 3:48 So, got merged in, and I felt pretty good about it.
- 3:54 Nice to get some praise from Peter.
- 3:55 It was my first contribution to the project.
- 3:59 It's very cool.
- 3:59 So what does it look like exactly like in the config?
- 4:03 I'm just gonna show like a kind of narrow part of the config here, but you have your gateway and essentially you no longer need the token like I mentioned.
- 4:14 The mode is obviously different so it's called trusted proxy now.
- 4:16 And then there's some new properties you have to add.
- 4:18 So there's trusted proxies and this is essentially the proxy that is gating access to the control plane, the gateway.
- 4:28 It's the IP addresses.
- 4:30 It could be one or more.
- 4:32 And aside from that, you have to have a trusted proxy section.
- 4:36 So you'll have a user header, which is, in my case, it's a JWT.
- 4:43 And then there's a required header section.
- 4:45 There's some optional ones, too.
loading