Istio Security Assessment
NCC-GOIST2005-013 on page 18, by default, the “profiling” mode is also enabled which runs go trace profiling tools5 on the pilot binary itself which contains stack, heap, and other process information about Pilot 0x405f77 0x405c3b 0x135de04 0x4674a1 # 0x135de03 k8s.io/client- go/tools/cache.(*controller).Run.func1+0x33 k8s.io/client- go@v0.18.0/tools/cache/controller.go:124 32 @ 0x4374a0 0x447663 0x1355d95 0x135561b 0x4674a1 # 0x1355d94 k8s.io/client- go/tools/cache.(*Reflector).watchHandler+0x1e4 k8s.io/client- go@v0.18.0/tools/cache/reflector.go:430 # 0x135561a k8s.io/client- go/tools/cache.(*Reflector).ListAndWatch+0xa1a0 码力 | 51 页 | 849.66 KB | 1 年前3Istio as an API Gateway
Monitoring, Tracing API Gateway + Service Mesh together! Limitations of This Approach ● Maintaining Two Tools ● Maintaining Two Expert Pools Istio as the API Gateway Advantages Advantages ● Same abstractions0 码力 | 27 页 | 1.11 MB | 1 年前3Istio-redirector: the way to go to manage thousands of HTTP redirections
SEO specialist creates the file manually Matching old URLs with the new ones based on different tools (crawler, etc..) How does it work ? #IstioCon Creating the .csv Importing the file Generating0 码力 | 13 页 | 1.07 MB | 1 年前3IstioCon 2022 Report
presented in English, with captioning. 4 Workshops for providing hands-on practice with specific tools/platforms 3 Listening sessions where users provided feedback on specific developments in the0 码力 | 20 页 | 2.44 MB | 1 年前3Service mesh security best practices: from implementation to verification
Edge Cluster Workload Operation GitOps Gatekeeper RBAC Audit log Metrics Security testing tools Security dashboard Prometheus Kiali Security Lifecycle Concepts Secure Monitor Enforce Verify0 码力 | 29 页 | 1.77 MB | 1 年前3Secure your microservices with istio step by step
testing@secure.istio.io jwksUri: "https://raw.githubusercontent.com/istio/istio/re lease-1.8/security/tools/jwt/samples/jwks.json" apiVersion: security.istio.io/v1beta1 kind: AuthorizationPolicy metadata:0 码力 | 34 页 | 67.93 MB | 1 年前3Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio
the Specs on our Global Control Plane ● Realized on hardware LBs ● Internal orchestration & UI tools to use Access Point specs ● Standardization provides flexibility to switch backend implementations0 码力 | 22 页 | 505.96 KB | 1 年前3Performance tuning and best practices in a Knative based, large-scale serverless platform with Istio
ing-Istio- Performance ● Debugging Envoy and Istiod https://istio.io/latest/docs/ops/diagnostic-tools/proxy- cmd/ ● Pilot agent config https://istio.io/latest/docs/reference/commands/pilot-agent/ ●0 码力 | 23 页 | 2.51 MB | 1 年前3Is Your Virtual Machine Really Ready-to-go with Istio?
user ■ Private key and CSR generation limited to Istio agent (no support of other provisioner tools and HSM incompatible) ■ Limitations to audit (proactively secure) ● VM cert extensibility ○ No0 码力 | 50 页 | 2.19 MB | 1 年前3
共 9 条
- 1