Istio Security Assessment
operational deployment • preview: enables experimental features The “default” profile (used to generate the Kubernetes config shown in Appendix D on page 44) is “recommend for production deployments” Description As discussed in the istio/istio GitHub repository’s issue #25652,12 as part of its process to generate Envoy configurations from DestinationRule policies, Istio translates the Destina- tionRule trafficPolicy • Envoy Configuration Template Rendering: The current implementation used by pilot-a gent to generate the initial Envoy proxy configuration uses the Golang text/template package to render a text template0 码力 | 51 页 | 849.66 KB | 1 年前3Secure your microservices with istio step by step
metadata: name: reviews spec: host: reviews trafficPolicy: tls: mode: ISTIO_MUTUAL 1) Generate client and server certificates and keys 2) Create a secret for the ingress gateway: productpage-credential port to send request: From curl command: need attaching certificate file Access productpage 1) Generate client and server certificates and keys 2) Create a secret for the ingress gateway: productpage-credential0 码力 | 34 页 | 67.93 MB | 1 年前3Accelerate Istio-CNI with ebpf
may conflict due to same src/dst ip address #IstioCon Use pod ip as hash key Use pod_ip to generate a unique key is a way to distinguish socket from different network namespace #IstioCon Outbound0 码力 | 15 页 | 658.90 KB | 1 年前3Using ECC Workload Certificates (pilot-agent environmental variables)
… ASN1 OID: prime256v1 NIST CURVE: P-256 istiod will generate a self-signed CA certificate using RSA if plugged in custom CA certificates aren’t specified0 码力 | 9 页 | 376.10 KB | 1 年前3How HP set up secure and wise platform with Istio
Metrics Distributed Traces Access Logs #IstioCon Excellent Observability Istio(envoy) can generate access logs for service traffic in a configurable set of formats #IstioCon Excellent Observability0 码力 | 23 页 | 1.18 MB | 1 年前3宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格
Indicates that the configurations to be added to the group will use macro APIs that automatically generate Istio APIs under the hood. ● Direct: Indicates that the configurations to be added to the group0 码力 | 30 页 | 4.79 MB | 5 月前3Performance tuning and best practices in a Knative based, large-scale serverless platform with Istio
Benchmark: Kperf (https://github.com/knative-sandbox/kperf) is a benchmark tool for Knative which can generate specific Knative Service provisioning workload and provides aggregated data of Knative Service0 码力 | 23 页 | 2.51 MB | 1 年前3Is Your Virtual Machine Really Ready-to-go with Istio?
VMs ● Onboard steps ○ Setup Internal Load Balancers (ILBs) for Kube DNS, Pilot, Mixer and CA ○ Generate configs for VMs, incl. `cluster.env`, DNS config, Istio authN secrets etc. ○ Setup dnsmasq, Istio0 码力 | 50 页 | 2.19 MB | 1 年前3全栈服务网格 - Aeraki 助你在 Istio 服务网格中管理任何七层流量
Envoy Code changes at the Pilot side: ● Add AwesomeRPC support in VirtualService API ● Generate LDS/RDS for Envoy Filter AwesomeRPC Filter ● Decoding/Encoding ● Routing ● Load balancing ● Circuit0 码力 | 29 页 | 2.11 MB | 1 年前3Istio is a long wild river: how to navigate it safely
Sidecar CRDs Stabilizing Istio ● Do not expose Sidecar CRD to users, use a service definition to generate Sidecar ● Use protocol specific traffic sniffing (i.e. gRPC call discovery) to find out dependencies0 码力 | 69 页 | 1.58 MB | 1 年前3
共 11 条
- 1
- 2