Automate mTLS communication with GoPay partners with Istio
TLS ○ Centralized Certificate Management ○ Ingress mutual TLS ○ Egress mutual TLS ● Challenge & Future Works GoPay & Istio About ● A few hundred developers ● Multiple Kubernetes Clusters ● 250+ microservices Challenge & Future Works Challenge ● Client egress communication sometime got 503 error (Istio #26990). This is fixed by adding retry mechanism in the Virtual Service object. Future Works ● Migrating0 码力 | 16 页 | 1.45 MB | 1 年前3Istio Security Assessment
create an additional resource type for ingress gateways to abstract their configuration and enable future features. This could be used, in combination with a new Gateway resource field, to implement a two-way Permissive Kubernetes RBAC Permissions may allow excessive write access within a names- pace. If, in the future, a privilege escalation vector is identified for any of the Kubernetes API Groups, escape from a field for trafficPolicy.tls will result in the proxy not verifying the server’s certificate. For future versions of Istio, when a DestinationRule or similar client-side configuration declar- ing a remote0 码力 | 51 页 | 849.66 KB | 1 年前3IstioCon 2022 Report
Participant feedback The majority of participants agree that they had enough information about the future of Istio project. Most participants felt empowered to use Istio after attending the conference helpful for the non-native English speakers. "Wonderful event and speakers,looking forward to join future events" "I enjoy the single track mode of this conference as well as the very quick access0 码力 | 20 页 | 2.44 MB | 1 年前3Kubernetes容器应用基于Istio的灰度发布实践
predictive statements including, without limitation, statements regarding the future financial and operating results, future product portfolio, new technology, etc. There are a number of factors that could0 码力 | 38 页 | 14.93 MB | 1 年前3Kubernetes容器应用基于Istio的灰度发布实践
predictive statements including, without limitation, statements regarding the future financial and operating results, future product portfolio, new technology, etc. There are a number of factors that could0 码力 | 34 页 | 2.64 MB | 5 月前3Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio
#IstioCon Agenda ● Introduction ● Applications Deployment ● Service Mesh Journey ● Scale Testing ● Future Direction #IstioCon Introduction: eBay at a glance 185M Number of Active Buyers worldwide 19M PILOT_DEBOUNCE_AFTER, PILOT_DEBOUNCE_MAX, PILOT_PUSH_THROTTLE, etc. params of Istio Pilot #IstioCon Future Direction ● Support for on-demand config pushes to Envoy via Incremental XDS ● Support for multiple0 码力 | 22 页 | 505.96 KB | 1 年前3Istio audit report - ADA Logics - 2023-01-30 - v1.0
several high-level goals: 1. Formalise a threat model of Istio to guide the security audit as well as future security audits. 2. Carry out a manual code audit for security issues. 3. Review the fixes for since all Istio team members that were involved in the previous security have le� the project. In future security audits we recommend more transparent and public tracking of issues, and explicit notions0 码力 | 55 页 | 703.94 KB | 1 年前3Using ECC Workload Certificates (pilot-agent environmental variables)
their use are considered experimental. There is no guarantee that they will not be deprecated in a future release. Use at your own discretion. ● To enable this, users must set the ECC_SIGNATURE_ALGORITHM0 码力 | 9 页 | 376.10 KB | 1 年前3IstioCon 2021 Report
Participant feedback The majority of participants agree that they had enough information about the future of Isito project. Most participants felt empowered to use Istio after attending the conference0 码力 | 18 页 | 912.89 KB | 1 年前3Performance tuning and best practices in a Knative based, large-scale serverless platform with Istio
PILOT_ENABLE_FLOW_CONTROL environment variable in Istiod. o Final solution is envoy delta-XDS push in future Istio release. Istio scalability optimization during Knative Service provisioning • support for0 码力 | 23 页 | 2.51 MB | 1 年前3
共 11 条
- 1
- 2