Is Your Virtual Machine Really Ready-to-go with Istio?
#IstioCon Is Your Virtual Machine Really Ready-to-go with Istio? Kailun Qin, Intel Haoyuan Ge #IstioCon Quick Summary (from Google Cloud Next ’19 [1]) VM works on Istio! [1] Istio Service Mesh Multi Clouds #IstioCon Istio VM Integration is? A Tumultuous Odyssey… [1] Istio 1.8: A Virtual Machine Integration Odyssey, Jimmy Song #IstioCon V0.2 Mesh Expansion ● Prerequisites ○ IP connectivity workloads themselves #IstioCon V1.6-1.8 Better VM Workload Abstraction Item Kubernetes Virtual Machine Basic schedule unit Pod WorkloadEntry Component Deployment WorkloadGroup Service registry and0 码力 | 50 页 | 2.19 MB | 1 年前3Using Istio to Build the Next 5G Platform
Aspen Mesh. All rights reserved. How to Make Legacy NFs Talk to CNFs in the Mesh UDM Virtual Machine Namespace SMF SMF Frontend UDM Egress Gateway Redis DB SMF App X certificates at gateways Learnings Along the Way 14 ©2021 Aspen Mesh. All rights reserved. ● 4G to 5G translation (Protocols like Diameter, SCTP, GTP) ● High speed data path (SR-IOV/DPDK) ● Customizing workload0 码力 | 18 页 | 3.79 MB | 1 年前3Istio audit report - ADA Logics - 2023-01-30 - v1.0
mode is enabled. As stated by the crypto/tls documentation: “In this mode, TLS is susceptible to machine-in-the-middle attacks unless custom verification is used. This should be used only for testing or http request that would be passed into httputil.DumpRequest() which could exhaust memory of the machine. The following demonstrates the issue: 1 package main 48 Istio Security Audit, 2023 2 3 4 5 panic(err) } fmt.Println("Here") } This program will not print out “Here” and will cause the machine to be inoperable from memory exhaustion. An attacker could exploit this by repeatedly sending large0 码力 | 55 页 | 703.94 KB | 1 年前3Building resilient systems inside the mesh: abstraction and automation of Virtual Service generation
the mesh: abstraction and automation of Virtual Service generation Vladimir Georgiev, Thought Machine #IstioCon Sync calls failures inside the mesh ● Everyone says to fail fast and retry quickly, definition Greeting service example #IstioCon Please Build System ● https://github.com/thought-machine/please ● Uses BUILD and allows for creation of miscellaneous rules Misc please rule for autogeneration0 码力 | 9 页 | 1.04 MB | 1 年前3Local Istio Development
speeds - Expensive #IstioCon Local Machine Local Cluster + Registry docker push kubectl apply docker pull Local Kubernetes Local Registry #IstioCon Local Machine Local Cluster + Registry docker0 码力 | 16 页 | 424.31 KB | 1 年前3Istio 2021 Roadmap A heartwarming work of staggering predictability
Discovery Service (SDS) ○ Auto mTLS ● API and feature promotion ○ Networking/Security APIs ○ Virtual Machine expansion/Multi cluster mesh https://istio.io/latest/blog/2020/tradewinds-2020/ #IstioCon Impact Feature Graduation ● Enhancement workflow ○ CNI ○ IPv6 ○ Dual-stack (IPv6/IPv6) ○ Virtual Machine Expansion ○ Multi cluster mesh ○ Helm v3 life-cycle management ● Evaluate current feature status0 码力 | 17 页 | 633.89 KB | 1 年前3Istio 在 Free Wheel 微服务中的实践
Istio从架构上可以分为4个板块: • Istio Proxy: Mesh的基础 • 网络安全:兼容Spiffe标准实现 • 配置管理:为C++实现的Proxy接 入k8s的动态配置管理 • Attribute Machine: 授权,Quota ,Tracing,监控的基础 Istio管理下的微服务 • 右图是部署mock1.v1 Pod之后发生的事 情: • Sidecar Injection: 注入initContainer0 码力 | 31 页 | 4.21 MB | 1 年前3Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio
Oracle, MySQL, etc. ○ Big data systems & Pipelines - Hadoop, Apache Spark, Apache Flink, etc. ○ Machine Learning Platforms - Tensorflow, PyTorch, Jupyter Notebook, etc. ○ Central Logging & Tracing - Prometheus0 码力 | 22 页 | 505.96 KB | 1 年前3Istio Security Assessment
with the versions of Istio relevant to this assessment. These steps assume a Ubuntu 18.04.4 LTS machine with minikube20 configured to use KVM, and Go installed. The latest Istio documentation for installing0 码力 | 51 页 | 849.66 KB | 1 年前3
共 9 条
- 1