apiVersion: security.istio.io/v1beta1 kind: RequestAuthentication metadata: name: keycloak-jwt namespace: istio-system spec: selector: matchLabels: app: istio-ingressgateway jwtRules: - # The `issuer` must be replaced with a Kustomize patch. issuer: PATCH_ME jwksUri: PATCH_ME forwardOriginalToken: true outputClaimToHeaders: - header: kubeflow-userid claim: email - header: kubeflow-groups claim: groups - header: x-auth-request-user claim: sub fromHeaders: - name: Authorization prefix: "Bearer "