Istio Security Assessment
hardening controls and should be replaced with a more secure-by-default option. • The Pilot admin interface exposes unnecessary ser- vices and is accessible to anyone within a default cluster. • The Envoy 017 High Ingress Gateway Configuration Generation Enables Route Hijacking 023 High Pilot Debug Interface Exposes Sensitive Information 002 Medium Default Production Profile Not Sufficiently Hardened 003 File Permissions Set 007 Low Istio Client-Side Bypasses 014 Low Sidecar Envoy Administrative Interface Exposed To Workload Containers 018 Low DestinationRules Without CA Certificates Field Do Not Validate0 码力 | 51 页 | 849.66 KB | 1 年前3全栈服务网格 - Aeraki 助你在 Istio 服务网格中管理任何七层流量
balancing at requet level ○ HTTP host/header/url/method, ○ Thrift service name/method name ○ Dubbo Interface/method/attachment ○ ... ● Fault Injection with application layer error codes ○ HTTP status code ■ 地域感知负载均衡 ■ 熔断 ■ 基于版本的路由 ■ 基于 Method 的路由 ■ 基于 Header 的路由 ○ 可观测性:七层(请求级别)Metrics ○ 安全:基于 Interface/Method 的服务访问 控制 #IstioCon Aeraki Demo: 用户请求和批处理任务隔离(Dubbo) 场景:隔离处理用户请求和批处理任务的服务实例,为用户请求留出足够的处理能0 码力 | 29 页 | 2.11 MB | 1 年前35 tips for your first Istio.io Contribution
Me I’m a high schooler who loves learning about everything related to computers, especially interface design. I started working on Istio last summer. Istio.io Work Automation Indicator #7734 Add0 码力 | 14 页 | 717.74 KB | 1 年前3Istio Meetup China 服务网格安全 理解 Istio CNI
static) into Pod IP addresses CNI plugins: allocate ip addresses for workloads exist in nodes CNI interface Calico Antrea Flannel Istio CNI CNI Daemonset Calico Antrea Flannel Istio CNI Networking lifecycle0 码力 | 19 页 | 3.17 MB | 1 年前3Developing & Debugging WebAssembly Filters
rust -t webassemblyhub.io/yuval/addheader-rust:v1 ./addheader-filter ABI: Application Binary Interface 13 | Copyright © 2020 > meshctl wasm push webassemblyhub.io/yuval/addheader-rust:v1 Build Store0 码力 | 22 页 | 2.22 MB | 1 年前3Is Your Virtual Machine Really Ready-to-go with Istio?
Concurrency limitations ■ Lack of docs etc. #IstioCon VM High Performance Networking ● VM Host IO interface ○ Relay ■ DPDK ○ Passthrough ■ SRIOV ● SRIOV ○ Single Root I/O Virtualization ● SIOV ○0 码力 | 50 页 | 2.19 MB | 1 年前3
共 6 条
- 1