Istio Security Assessmentgaps in documentation include: • /docs/ops/best-practices/security/: This section only provides 2 general recommendations. Use namespaces for isolation (a contentious perspective) and configured third party services 27 | Google Istio Security Assessment Google / NCC Group Confidential Note: As with general direct Pod connections involving Istio, it may be necessary for the client to bind to 127.0.0.6 as init containers — for which container specs may be queried directly through Kubernetes APIs — in general, they would be no-less opaque than the implementations used by CNI providers. 18https://istio.i0 码力 | 51 页 | 849.66 KB | 1 年前3
Istio audit report - ADA Logics - 2023-01-30 - v1.0This can lead to system resource exhaustion if a large byte buffer is read into memory. Case 1 A general Get function that makes an http request and reads the entire response into memory: https://github internal documentation that had been produced as part of the mitigation process. We then looked for public documentation related to the issues in the audit report. Finally we evaluated the affected code parts Logics auditors found some shortcomings in how the issues had been approached on the Istio side. In general, we found limited tracking, both internally and publicly. Upon request, the Istio team had little0 码力 | 55 页 | 703.94 KB | 1 年前3
5 tips for your first
Istio.io Contribution#IstioCon Commits ● For anything larger or bug fixes, create an issue and ask around for opinions ● General Contributing Guide ● Contributing Documentation: https://istio.io/latest/about/contribute/ #IstioCon0 码力 | 14 页 | 717.74 KB | 1 年前3
Istio at Scale: How eBay is building a massive Multitenant Service Mesh using IstioProgramming Languages - Java, Python, Go lang, Scala, etc. ● Running on variety of Hardware ○ General-purpose x86 servers ○ GPUs #IstioCon Application Deployment: Cloud Layout ● Region: A metro region0 码力 | 22 页 | 505.96 KB | 1 年前3
Using ECC Workload
Certificates
(pilot-agent environmental variables)sha256WithRSAEncryption … Subject: Subject Public Key Info: Public Key Algorithm: id-ecPublicKey Public-Key: (256 bit) pub:0 码力 | 9 页 | 376.10 KB | 1 年前3
生产环境 istioruntime app dev prod dev prod internal external on-prem dev prod public cloud gke dev prod dev prod internal external on-prem internet external internal DMZ0 码力 | 42 页 | 3.45 MB | 1 年前3
宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格integration ● On-prem, AWS, Azure, GCP, OpenShift ● 10000+ core business apps ● Plan to move to public cloud in 18 months ● Using F5 to distribute traffic at the DMZ zone Solving the OSS Istio pain0 码力 | 30 页 | 4.79 MB | 6 月前3
Performance tuning and best practices in a Knative based, large-scale serverless platform with Istiothat can host all of your cloud native workloads: https://www.ibm.com/cloud/code-engine ● Kperf, a public Knative benchmark tool helps everyone to understand the issue and accelerate the whole debug and0 码力 | 23 页 | 2.51 MB | 1 年前3
共 8 条
- 1













