SberBank story:
moving Istio from PoC to productionshares in Russia, % 32.2 42.3 23.5 44.9 Unlimited throughput Improved performance because of elimination of integration intermediary Integration expenses reduction Cloud oriented technology Control0 码力 | 14 页 | 1.68 MB | 1 年前3
Istio audit report - ADA Logics - 2023-01-30 - v1.0other types of implementation issues in the Go programming language such as NULL-pointers, out-of-bounds, race conditions, resource exhaustion issues and other issues stemming from improper usage of the 86 Description The Helm chart fetching and extraction logic of the Istio Operator has an out-of-bounds file write vulnerability. If the Operator runs with high privileges, this could lead to remote code A header.Name containing patterns such as .. could traverse the file system and perform out of bounds file writes. https://github.com/istio/istio/blob/d0705cf0ed5591cc26c08001f3faab0a880aec48/operato0 码力 | 55 页 | 703.94 KB | 1 年前3
5 tips for your first
Istio.io Contributionupdate/create a test if the page changed is tested! #IstioCon Run make lint locally to verify changes and check for problems Click on the Netlify preview to view updates as if they were live #IstioCon Summary to create issues, ask around, and share your ideas ● Join the Working Group ● Contributing ○ Check out the style guides for documentation ○ Look into writing tests and how they work ○ We are here0 码力 | 14 页 | 717.74 KB | 1 年前3
Istio Meetup China 服务网格安全 理解 Istio CNIBypassing all iptable rules set by data plane proxies Troubleshooting Istio CNI Check the istio proxy container through nsenter Check CNI logs in kubelet (journalctl) Will do: grafana board istio CNI logging0 码力 | 19 页 | 3.17 MB | 1 年前3
Istio is a long wild river: how to navigate it safelyadmission webhooks (OPA Gatekeeper) to ○ protect the resources ○ check what cannot be checked at linter-level (inventory) Please check my last year presentation: “Preparing the guardrails for Istio0 码力 | 69 页 | 1.58 MB | 1 年前3
Istio-redirector: the way
to go to manage
thousands of HTTP
redirections>26k redirections are now running in production without any impact on performances! #IstioCon Check it out on Github https://github.com/blablacar/istio-redirector And leave a star ? #IstioCon How0 码力 | 13 页 | 1.07 MB | 1 年前3
Set Sail for a
Ship-Shape Istio Releaseit does, the developer can easily add a release note. ● If it doesn’t, then the developer can check a box and the pull request will merge. New System Release Notes #IstioCon Release Notes: As0 码力 | 18 页 | 199.43 KB | 1 年前3
Istio 在 Free Wheel 微服务中的实践是对Proxy上报的Attribute的特定处 理机制的框架,支持四类: • Preprocess: 汇总流量相关元数据 和环境(k8s)相关的元数据 • Report: 上报数据 • Check: 决策是否允许当前访问 • Quota: 决策容量是否足够 Mixer or Sidecar,这是一个问题 • Mixer提供了一种非常灵活的模型,让Handler可以在流量中动态的选0 码力 | 31 页 | 4.21 MB | 1 年前3
探讨和实践基于Istio的微服务治理事件监控logfile Proxy Transaction ID Transaction ID …Commit to Client Success 成就客户卓越Mixer组件功能介绍Mixer的介绍 • Check:也叫precondition,前置条件检查, 比如说黑白名单,权限。 • Quota:访问次数 • Report: 日志。Mixer的二次开发流程Mixer插件工作模型 上述的过程中,E0 码力 | 29 页 | 8.37 MB | 6 月前3
Secure your microservices with istio step by step○ kubectl exec-c istio-proxy curl localhost:15000/config_dump #IstioCon Istio identity – check configuration result ● Result: cert generated automatically with Istio identity 1) Apply peer-authentication 0 码力 | 34 页 | 67.93 MB | 1 年前3
共 12 条
- 1
- 2













