Istio is a long wild river: how to navigate it safelyyour fights, start small Stabilizing Istio Start with few simple features such as: ● Injecting sidecars, HTTP/2 LoadBalancing ● Traffic shifting for canaries Build confidence in the system and understanding First, headless services, now labels... Who said that migrating to Istio is only about adding sidecars?? 50 Label selector updates for app and version labels Adopting Istio Fair enough, let’s do the IstioOperator manifest. 55 Istio proxy performance and capacity Adopting Istio ● Putting sidecars everywhere has a cost ○ Latency ○ Compute resources The Istio 1.9 community reference values0 码力 | 69 页 | 1.58 MB | 1 年前3
Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istio& thousands of Pods with sidecar Envoys ○ Measure Config convergence time ■ Time taken by all sidecars to get config from Pilot without any errors ■ For thousands of services & endpoints ■ With different ○ Disabled egress traffic to restrict config pushed to sidecars ● Main Takeaways ○ P99.9 time from single Pilot instance to 0 - 3,000 sidecars < 1 second ○ Pilot CPU & memory within acceptable limits:0 码力 | 22 页 | 505.96 KB | 1 年前3
Istio Security Assessment“distroless” version of it’s Docker image which builds a minimal, hardened version that can be used for Sidecars. These types of security controls should not be optional. Reproduction Steps Attach to a Pod that Distroless image which can be used by other Istio control plane components (like Pilot) as well as the sidecars used by Pods and workloads. Make this configuration the default option for all systems possible on how to disable them when users want to opt-out of these controls. This should be enabled for Sidecars and services within the Istio control plan as well. 23 | Google Istio Security Assessment Google0 码力 | 51 页 | 849.66 KB | 1 年前3
IstioCon2023 Welcome KeynoteWhat’s New Since 2022 CNCF Graduation Ambient Mesh A new dataplane mode for Istio without sidecars. Graduated Announcing Istio's graduation within the CNCF Join CNCF Istio has applied to0 码力 | 14 页 | 1.31 MB | 1 年前3
How HP set up secure and
wise platform with Istiodefinition HTTP filters Network filters UDP listener filters … Match outbound listeners in all sidecars Or Istio gateway The Lua code that Envoy will execute. Which port number the filter will apply0 码力 | 23 页 | 1.18 MB | 1 年前3
在Kubernetes上部署高可用的Service Mesh监控API TargetsGlobal view - Querier ● Stateless, horizontally scalable. ● Fan out queries to all sidecars and stores. Merge and deduplicate query results. ● Global view + HAUnlimited Retention ● Prometheus0 码力 | 35 页 | 2.98 MB | 6 月前3
Service mesh security best practices: from implementation to verification is natively encrypted, such as HTTPS 3. use k8s network policies to limit traffic bypassing sidecars Cluster security best practices: safely handle policy exceptions Cluster security Access control0 码力 | 29 页 | 1.77 MB | 1 年前3
Istio + MOSN 在 Dubbo 场景下的探索之路资源名称 CDS EDS LDS RDS Virtualservices ✔ Gateways Serviceentries Destinationrules Envoyfilters Sidecars ConfigClientQuotaspecs ConfigClientQuotaspecbindings Authorizationpolicies Requestauthentications0 码力 | 25 页 | 3.71 MB | 6 月前3
Performance tuning and best practices in a Knative based, large-scale serverless platform with Istioservice access cross user namespace. o The sidecar CR helps to limit the known egress hosts for sidecars, sidecar needs to knows mesh in his own user namespace only. o We can limit the mesh size to0 码力 | 23 页 | 2.51 MB | 1 年前3
Dapr july 2020 security audit reportInstead, they can also be used to directly sign arbitrary certificates and communicate with other sidecars. HTTP request: POST /mutate HTTP/2 Host: 10.0.42.140 Content-Type: application/json Content-Length:0 码力 | 19 页 | 267.84 KB | 1 年前3
共 13 条
- 1
- 2













