 Istio Security AssessmentMUTUAL_TLS” • Create a istio setup with control plane security enabled: istioctl install --set values.global.controlPlaneSecurityEnabled=true • Deploy the customized default policy • Start a Pod in a namespace Pilot at runtime. This web interface also allows unauthenticated users to force force all Istio objects to sync their current configuration. This in itself is not malicious but could cause a denial-of-service attack- ers with unauthenticated access to sensitive information such as certificates, keys, names of objects in the clusters, and more that should be protected. goroutine profile: total 380 32 @ 0x4374a0 0x405f770 码力 | 51 页 | 849.66 KB | 1 年前3 Istio Security AssessmentMUTUAL_TLS” • Create a istio setup with control plane security enabled: istioctl install --set values.global.controlPlaneSecurityEnabled=true • Deploy the customized default policy • Start a Pod in a namespace Pilot at runtime. This web interface also allows unauthenticated users to force force all Istio objects to sync their current configuration. This in itself is not malicious but could cause a denial-of-service attack- ers with unauthenticated access to sensitive information such as certificates, keys, names of objects in the clusters, and more that should be protected. goroutine profile: total 380 32 @ 0x4374a0 0x405f770 码力 | 51 页 | 849.66 KB | 1 年前3
 Istio at Scale: How eBay is building a massive Multitenant Service Mesh using IstioHierarchy of control planes ● Global Control Plane ○ Users provide application specs to Global Control-Plane ○ Syncs specs to AZ control-planes ○ Hosts global services - Global IPAM, Access-control Policy Cluster K8s Cluster K8s Cluster AZ Control Plane AZ Control Plane AZ Control Plane Global Control Plane Region Rn Delegate #IstioCon Load balancing & Traffic Flow ● Two tiers of hardware ... #IstioCon AccessPoint Spec Step 1: Access Point Spec ● Create the Specs on our Global Control Plane ● Realized on hardware LBs ● Internal orchestration & UI tools to use Access Point0 码力 | 22 页 | 505.96 KB | 1 年前3 Istio at Scale: How eBay is building a massive Multitenant Service Mesh using IstioHierarchy of control planes ● Global Control Plane ○ Users provide application specs to Global Control-Plane ○ Syncs specs to AZ control-planes ○ Hosts global services - Global IPAM, Access-control Policy Cluster K8s Cluster K8s Cluster AZ Control Plane AZ Control Plane AZ Control Plane Global Control Plane Region Rn Delegate #IstioCon Load balancing & Traffic Flow ● Two tiers of hardware ... #IstioCon AccessPoint Spec Step 1: Access Point Spec ● Create the Specs on our Global Control Plane ● Realized on hardware LBs ● Internal orchestration & UI tools to use Access Point0 码力 | 22 页 | 505.96 KB | 1 年前3
 Sketch a Mesh for You1 | Copyright © 2020 2 | Copyright © 2020 CHRISTIAN POSTA Global Field CTO, Solo.io @christianposta christian@solo.io https://blog.christianposta.com https://slideshare.net/ceposta 3 | Copyright0 码力 | 13 页 | 2.71 MB | 1 年前3 Sketch a Mesh for You1 | Copyright © 2020 2 | Copyright © 2020 CHRISTIAN POSTA Global Field CTO, Solo.io @christianposta christian@solo.io https://blog.christianposta.com https://slideshare.net/ceposta 3 | Copyright0 码力 | 13 页 | 2.71 MB | 1 年前3
 Accelerate Istio-CNI with ebpffrom applications in user space #IstioCon Work Flow of Acceleration ● Attach SOCK_OPS program to global cgroup ● Capture socket in established state and add to hashmap ● Attach sk_skb program to hashmap0 码力 | 15 页 | 658.90 KB | 1 年前3 Accelerate Istio-CNI with ebpffrom applications in user space #IstioCon Work Flow of Acceleration ● Attach SOCK_OPS program to global cgroup ● Capture socket in established state and add to hashmap ● Attach sk_skb program to hashmap0 码力 | 15 页 | 658.90 KB | 1 年前3
 Developing & Debugging WebAssembly FiltersSecurity (EW) Observability Zero-trust Approval Processes Rollback Delegation WASM Multi Cluster Global Service Failover Multi Mesh 4 | Copyright © 2020 Orders Citadel Pilot Galley User Account0 码力 | 22 页 | 2.22 MB | 1 年前3 Developing & Debugging WebAssembly FiltersSecurity (EW) Observability Zero-trust Approval Processes Rollback Delegation WASM Multi Cluster Global Service Failover Multi Mesh 4 | Copyright © 2020 Orders Citadel Pilot Galley User Account0 码力 | 22 页 | 2.22 MB | 1 年前3
 宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格a LoadBalancer Architecture ● Multi cluster ● Multi mesh ● Components ○ Management plane ○ Global control plane ○ Local control plane TSB Management Plane ● Front Envoy ● Multi Cluster support0 码力 | 30 页 | 4.79 MB | 6 月前3 宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格a LoadBalancer Architecture ● Multi cluster ● Multi mesh ● Components ○ Management plane ○ Global control plane ○ Local control plane TSB Management Plane ● Front Envoy ● Multi Cluster support0 码力 | 30 页 | 4.79 MB | 6 月前3
 Istio audit report - ADA Logics - 2023-01-30 - v1.0HTTPFetcher which prints out the size of the response body a�er it has been read into memory. The global variable bufferSize can be modified to demonstrate that the response body will be read no matter0 码力 | 55 页 | 703.94 KB | 1 年前3 Istio audit report - ADA Logics - 2023-01-30 - v1.0HTTPFetcher which prints out the size of the response body a�er it has been read into memory. The global variable bufferSize can be modified to demonstrate that the response body will be read no matter0 码力 | 55 页 | 703.94 KB | 1 年前3
共 7 条
- 1













