 Istio Security AssessmentNCC-GOIST2005-013 on page 18, by default, the “profiling” mode is also enabled which runs go trace profiling tools5 on the pilot binary itself which contains stack, heap, and other process information about Pilot 0x405f77 0x405c3b 0x135de04 0x4674a1 # 0x135de03 k8s.io/client- go/tools/cache.(*controller).Run.func1+0x33 k8s.io/client- go@v0.18.0/tools/cache/controller.go:124 32 @ 0x4374a0 0x447663 0x1355d95 0x135561b 0x4674a1 # 0x1355d94 k8s.io/client- go/tools/cache.(*Reflector).watchHandler+0x1e4 k8s.io/client- go@v0.18.0/tools/cache/reflector.go:430 # 0x135561a k8s.io/client- go/tools/cache.(*Reflector).ListAndWatch+0xa1a0 码力 | 51 页 | 849.66 KB | 1 年前3 Istio Security AssessmentNCC-GOIST2005-013 on page 18, by default, the “profiling” mode is also enabled which runs go trace profiling tools5 on the pilot binary itself which contains stack, heap, and other process information about Pilot 0x405f77 0x405c3b 0x135de04 0x4674a1 # 0x135de03 k8s.io/client- go/tools/cache.(*controller).Run.func1+0x33 k8s.io/client- go@v0.18.0/tools/cache/controller.go:124 32 @ 0x4374a0 0x447663 0x1355d95 0x135561b 0x4674a1 # 0x1355d94 k8s.io/client- go/tools/cache.(*Reflector).watchHandler+0x1e4 k8s.io/client- go@v0.18.0/tools/cache/reflector.go:430 # 0x135561a k8s.io/client- go/tools/cache.(*Reflector).ListAndWatch+0xa1a0 码力 | 51 页 | 849.66 KB | 1 年前3
 Istio as an API GatewayMonitoring, Tracing API Gateway + Service Mesh together! Limitations of This Approach ● Maintaining Two Tools ● Maintaining Two Expert Pools Istio as the API Gateway Advantages Advantages ● Same abstractions0 码力 | 27 页 | 1.11 MB | 1 年前3 Istio as an API GatewayMonitoring, Tracing API Gateway + Service Mesh together! Limitations of This Approach ● Maintaining Two Tools ● Maintaining Two Expert Pools Istio as the API Gateway Advantages Advantages ● Same abstractions0 码力 | 27 页 | 1.11 MB | 1 年前3
 Istio-redirector: the way
to go to manage
thousands of HTTP
redirectionsSEO specialist creates the file manually Matching old URLs with the new ones based on different tools (crawler, etc..) How does it work ? #IstioCon Creating the .csv Importing the file Generating0 码力 | 13 页 | 1.07 MB | 1 年前3 Istio-redirector: the way
to go to manage
thousands of HTTP
redirectionsSEO specialist creates the file manually Matching old URLs with the new ones based on different tools (crawler, etc..) How does it work ? #IstioCon Creating the .csv Importing the file Generating0 码力 | 13 页 | 1.07 MB | 1 年前3
 IstioCon 2022 Reportpresented in English, with captioning. 4 Workshops for providing hands-on practice with specific tools/platforms 3 Listening sessions where users provided feedback on specific developments in the0 码力 | 20 页 | 2.44 MB | 1 年前3 IstioCon 2022 Reportpresented in English, with captioning. 4 Workshops for providing hands-on practice with specific tools/platforms 3 Listening sessions where users provided feedback on specific developments in the0 码力 | 20 页 | 2.44 MB | 1 年前3
 Service mesh security best practices: from implementation to verification Edge Cluster Workload Operation GitOps Gatekeeper RBAC Audit log Metrics Security testing tools Security dashboard Prometheus Kiali Security Lifecycle Concepts Secure Monitor Enforce Verify0 码力 | 29 页 | 1.77 MB | 1 年前3 Service mesh security best practices: from implementation to verification Edge Cluster Workload Operation GitOps Gatekeeper RBAC Audit log Metrics Security testing tools Security dashboard Prometheus Kiali Security Lifecycle Concepts Secure Monitor Enforce Verify0 码力 | 29 页 | 1.77 MB | 1 年前3
 Secure your microservices with istio step by steptesting@secure.istio.io jwksUri: "https://raw.githubusercontent.com/istio/istio/re lease-1.8/security/tools/jwt/samples/jwks.json" apiVersion: security.istio.io/v1beta1 kind: AuthorizationPolicy metadata:0 码力 | 34 页 | 67.93 MB | 1 年前3 Secure your microservices with istio step by steptesting@secure.istio.io jwksUri: "https://raw.githubusercontent.com/istio/istio/re lease-1.8/security/tools/jwt/samples/jwks.json" apiVersion: security.istio.io/v1beta1 kind: AuthorizationPolicy metadata:0 码力 | 34 页 | 67.93 MB | 1 年前3
 Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istiothe Specs on our Global Control Plane ● Realized on hardware LBs ● Internal orchestration & UI tools to use Access Point specs ● Standardization provides flexibility to switch backend implementations0 码力 | 22 页 | 505.96 KB | 1 年前3 Istio at Scale: How eBay is building a massive Multitenant Service Mesh using Istiothe Specs on our Global Control Plane ● Realized on hardware LBs ● Internal orchestration & UI tools to use Access Point specs ● Standardization provides flexibility to switch backend implementations0 码力 | 22 页 | 505.96 KB | 1 年前3
 Performance tuning and best practices in a Knative based, large-scale serverless platform with Istioing-Istio- Performance ● Debugging Envoy and Istiod https://istio.io/latest/docs/ops/diagnostic-tools/proxy- cmd/ ● Pilot agent config https://istio.io/latest/docs/reference/commands/pilot-agent/ ●0 码力 | 23 页 | 2.51 MB | 1 年前3 Performance tuning and best practices in a Knative based, large-scale serverless platform with Istioing-Istio- Performance ● Debugging Envoy and Istiod https://istio.io/latest/docs/ops/diagnostic-tools/proxy- cmd/ ● Pilot agent config https://istio.io/latest/docs/reference/commands/pilot-agent/ ●0 码力 | 23 页 | 2.51 MB | 1 年前3
 Is Your Virtual Machine Really Ready-to-go with Istio?user ■ Private key and CSR generation limited to Istio agent (no support of other provisioner tools and HSM incompatible) ■ Limitations to audit (proactively secure) ● VM cert extensibility ○ No0 码力 | 50 页 | 2.19 MB | 1 年前3 Is Your Virtual Machine Really Ready-to-go with Istio?user ■ Private key and CSR generation limited to Istio agent (no support of other provisioner tools and HSM incompatible) ■ Limitations to audit (proactively secure) ● VM cert extensibility ○ No0 码力 | 50 页 | 2.19 MB | 1 年前3
共 9 条
- 1













