Istio is a long wild river: how to navigate it safelyRegions/languages supported: Base specs for Japan/Japanese ● Total number of listings to date: More than 2 billion *As of December 2020 Many sellers enjoy having the items they no longer need purchased stopped after any other container in a pod ● Adjust your pods terminationGracePeriodSeconds to be more than the sum of all sleeps in the preStop hooks. ➔ If the pod is terminated too early, connection draining only recommended if you know what you are doing. Once Kubernetes supports the sidecar pattern in a better way, these workarounds should be deprecated. 21 Shortcoming 2: Autoscaling multi-containers pods0 码力 | 69 页 | 1.58 MB | 1 年前3
Istio Security Assessmentworthwhile to create an Istio Hostname resource that can be referenced by Gateways, which would allow for better tracking of hostnames — and hostname collisions — in a Kubernetes cluster. This would also enable especially when relying on features like REGISTRIES_ONLY7 or Egress policies. A service mesh is different than a CNI in that one facilitates communications, and the other controls them. Istio’s service mesh is trafficPolicy.tls (ClientTLSSettings) field into Envoy’s UpstreamTlsContext ,13 and — for modes other than ISTIO_MUTUAL in which Istio generates the PKI to use — defaults to converting such fields that lack0 码力 | 51 页 | 849.66 KB | 1 年前3
Is Your Virtual Machine Really Ready-to-go with Istio?Extensibility #IstioCon Why Should Istio Support VMs ● ≈ Why VMs? ○ Technical reasons ■ Better known security controls ■ Better isolation (of resources, fault domains etc.) ■ Compatibility (non-Linux, unikernels) ExternalName ■ Service <-> DNS name ○ External IPs #IstioCon V1.1 ServiceEntry #IstioCon V1.6-1.8 Better VM Workload Abstraction A K8s Service and Pods Two separate object with distinct lifecycles it, w/o giving a first-class representation for the workloads themselves #IstioCon V1.6-1.8 Better VM Workload Abstraction Item Kubernetes Virtual Machine Basic schedule unit Pod WorkloadEntry0 码力 | 50 页 | 2.19 MB | 1 年前3
5 tips for your first
Istio.io Contributioncom/istio/istio/wiki/Reviewing-Pull-Requests #IstioCon Learn Istio is a complex project, and Istio.io is the perfect place to start committing. #IstioCon Connect With the Community ● Working groups - great way0 码力 | 14 页 | 717.74 KB | 1 年前3
Istio 2021 Roadmap A heartwarming work of staggering predictabilityArchitect, Aspen Mesh) Louis Ryan (Principal Engineer, Google) #IstioCon Highlights of 2020 ● Better life cycle management ○ Istioctl install & Operator support ● Architectural simplification ○ Monolith Promoting revision based upgrades ○ Support skip-level upgrades ○ Pre & Post Upgrade checks ○ Better testing mirroring production use cases ● Enhanced troubleshooting ● Aligning APIs with Istio user0 码力 | 17 页 | 633.89 KB | 1 年前3
宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格multi cluster at scale ● They can’t have k8s cluster in the DMZ zone ● Simpler and better VM onboarding expereince ● Better zero trust architecture DMZ F5 -> Two Tier Gateway • Istio Fundamentals (Free)0 码力 | 30 页 | 4.79 MB | 6 月前3
f5a Istio Adoption Cash AppInternal Presentation AGENDA Why? Reasons Options How? Strategy Compromise What could have been better? Learnings Hurdles What’s next? Projects Ideas Excitement! Internal Presentation New Square0 码力 | 15 页 | 2.20 MB | 1 年前3
Moving large scale consumer
e-commerce Infrastructure to
Mesh- Istio setup and Microservices ● Export metrics to central prometheus ● Outlier detection for better reliability ● Enable Zonal routing, zonal deployment and HPA ● Endpoint accessed by service via0 码力 | 14 页 | 1.76 MB | 1 年前3
Your laptop as part
of the service meshMocks are like any other software: ● Bugs ● Maintenance Why don’t you ? #IstioCon Can we do better ? #IstioCon What if ? #IstioCon EnvoyFilter - #IstioCon Envoy HTTP LuaFilter function en0 码力 | 30 页 | 555.24 KB | 1 年前3
Using ECC Workload
Certificates
(pilot-agent environmental variables)io/latest/docs/reference/commands/pilot-agent/#envvars Remember: Always look to see if there are other, better ways of enabling functionality; environmental variables are considered experimental. #IstioCon0 码力 | 9 页 | 376.10 KB | 1 年前3
共 17 条
- 1
- 2
相关搜索词
IstioislongwildriverhowtonavigateitsafelySecurityAssessmenttipsforyourfirstioContributiond1kIstio2021RoadmapNeerajLouis宋净超开源企业企业级服务如何落地网格f5aIstioAdoptionCashAppMovinglargescaleconsumercommerceInfrastructureMeshYourlaptopaspartoftheservicemeshUsingECCWorkloadCertificatespilotagentenvironmentalvariables













