全栈服务网格 - Aeraki 助你在 Istio 服务网格中管理任何七层流量
Mesh 中的七层流量管理能力 ❏ 几种扩展 Istio 流量管理能力的方法 ❏ Aeraki - 在 Isito 服务网格中管理所有七层流量 ❏ Demo - Dubbo Traffic Management ❏ MetaProtocol - Service Mesh 通用七层协议框架 #IstioCon Protocols in a Typical Microservice Application RabbitMQ … ● Cache: Redis, Memcached ... ● Database: mySQL, PostgreSQL, MongoDB ... ● Other Layer-7 Protocols: ... Control Plane (Traffic Management, Security, Observability) #IstioCon What Do Header Layer-7 Header Data Traffic Management for HTTP/gRPC - all good ● We get all the capabilities we mentioned on the previous slide Traffic Management for non-HTTP/gRPC - only layer-3 to layer-60 码力 | 29 页 | 2.11 MB | 1 年前3宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格
TSB: The Application-Aware Networking Platform Istio: Control Plane Tetrate Service Bridge: Management Plane Envoy: Data Plane Workload (Service) POD Workload (Service) POD Workload (Service) POD Workload Architecture ● Multi cluster ● Multi mesh ● Components ○ Management plane ○ Global control plane ○ Local control plane TSB Management Plane ● Front Envoy ● Multi Cluster support ● XCP Central -> Kubernetes Gateway API Use Case: A Financial Company Istio: Control Plane Tetrate Service Bridge: Management Plane Envoy: Data Plane Workload (Service) POD Workload (Service) POD Workload (Service) POD Workload0 码力 | 30 页 | 4.79 MB | 5 月前3Automate mTLS communication with GoPay partners with Istio
Agenda ● GoPay & Istio ● Before mutual TLS ● Implementing mutual TLS ○ Centralized Certificate Management ○ Ingress mutual TLS ○ Egress mutual TLS ● Challenge & Future Works GoPay & Istio About ● IP that used by all services) Implementing Mutual TLS Centralized Certificate Management ● Central certificate management manage our certificate lifecycle for HTTPS and mutual TLS communication. ●0 码力 | 16 页 | 1.45 MB | 1 年前3Kubernetes容器应用基于Istio的灰度发布实践
在Google:microservices become API Apigee API Management complements Istio with the robust features of Google Cloud's Apigee API management platform, Apigee Edge, by extending API management natively into the microservices0 码力 | 38 页 | 14.93 MB | 1 年前3Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio
Why Service Mesh? ● Current challenges include - ○ Manageability of Hardware Devices ■ Traffic Management & Security Enforcement ■ Updating hardware devices is slow ○ Achieving micro-segmentation at Discovery functions as features of the infrastructure - ○ Functions: TLS Termination, Traffic Management, Tracing, Rate Limiting, Protocol Adapter, Circuit breaker, Caching, etc. #IstioCon Service Architecture Evolving Security Current Status #IstioCon Step 1: Access Point Spec ● Capture Traffic Management & Routing intent as “Access Point” Specs ○ Leverage Istio object model: Gateway, VirtualService0 码力 | 22 页 | 505.96 KB | 1 年前3Istio Security Assessment
enabling the workload container to claim its ports. 7https://istio.io/latest/docs/tasks/traffic-management/egress/egress-control/#envoy-passthrough-to-external- services 27 | Google Istio Security Assessment restricting egress traffic to only Istio’s Egress gateway. 8https://istio.io/latest/docs/tasks/traffic-management/egress/egress-gateway/ 28 | Google Istio Security Assessment Google / NCC Group Confidential between these sidecars at a cluster level. Tools like Hashicorp vault provide addi- tional secret management controls and a Dynamic Admission Controller-based approaches such as OPA19 provide a means to help0 码力 | 51 页 | 849.66 KB | 1 年前3Is Your Virtual Machine Really Ready-to-go with Istio?
complexity ○ Need consistent policy enforcement ○ Need consistent metrics aggregation ● Traffic management ○ Load balancing for VMs, failover, A/B testing, modern rollouts for VM services ● Security workload certificate attributes #IstioCon Security & Usability Limitations (cont.) ● Access management: CNI needs improvements ○ Much required to avoid escalated Pod privileges ○ No support for smart Sidecar Offload ● Ultimate goal ○ Proxyless services (for high performance) ● Offload ○ Traffic management ○ Security (DDoS defense…) ● HW acceleration ○ Crypto ○ Rule matching ● Further isolation0 码力 | 50 页 | 2.19 MB | 1 年前3Istio audit report - ADA Logics - 2023-01-30 - v1.0
used on top of Kubernetes. It offers users easy access to features such as observability, traffic management and security without requiring users to add these to their application code. It also offers more ● Certificate management ● Authentication ● Authorization ● Policy Enforcement Points (PEPs) ● A set of Envoy proxy extensions to manage telemetry and auditing Certificate management Alongside each0 码力 | 55 页 | 703.94 KB | 1 年前3IstioCon2023 Welcome Keynote
ιστία) 1. sail What about the rest of the boat? Upcoming Talks: Aperture - Load Management Meshery - WASM plugin management Argo - Multi-cluster orchestration JP Morgan SLO Generation Reflecting on the0 码力 | 14 页 | 1.31 MB | 1 年前3Istio 2021 Roadmap A heartwarming work of staggering predictability
Mesh) Louis Ryan (Principal Engineer, Google) #IstioCon Highlights of 2020 ● Better life cycle management ○ Istioctl install & Operator support ● Architectural simplification ○ Monolith control plane Dual-stack (IPv6/IPv6) ○ Virtual Machine Expansion ○ Multi cluster mesh ○ Helm v3 life-cycle management ● Evaluate current feature status and fix gaps https://istio.io/latest/blog/2020/tradewinds-2020/0 码力 | 17 页 | 633.89 KB | 1 年前3
共 16 条
- 1
- 2