 Automate mTLS
communication with
GoPay partners with
IstioAutomate mTLS communication with GoPay partners with Istio Vijay Dhama, Gojek Zufar Dhiyaulhaq, Gojek Agenda ● GoPay & Istio ● Before mutual TLS ● Implementing mutual TLS ○ Centralized Certificate ● Central certificate management manage our certificate lifecycle for HTTPS and mutual TLS communication. ● Renew & sync to our Kubernetes cluster, also support syncing to VM with an agent installed automatically to mutual TLS by sidecar. Challenge & Future Works Challenge ● Client egress communication sometime got 503 error (Istio #26990). This is fixed by adding retry mechanism in the Virtual0 码力 | 16 页 | 1.45 MB | 1 年前3 Automate mTLS
communication with
GoPay partners with
IstioAutomate mTLS communication with GoPay partners with Istio Vijay Dhama, Gojek Zufar Dhiyaulhaq, Gojek Agenda ● GoPay & Istio ● Before mutual TLS ● Implementing mutual TLS ○ Centralized Certificate ● Central certificate management manage our certificate lifecycle for HTTPS and mutual TLS communication. ● Renew & sync to our Kubernetes cluster, also support syncing to VM with an agent installed automatically to mutual TLS by sidecar. Challenge & Future Works Challenge ● Client egress communication sometime got 503 error (Istio #26990). This is fixed by adding retry mechanism in the Virtual0 码力 | 16 页 | 1.45 MB | 1 年前3
 Set Sail for a
Ship-Shape Istio ReleaseWorking Group - Stability ● Standards and processes ○ Control plane behavior ○ Data plane communication ● Promote revision-based upgrades to stable and support skip-level revision-based upgrades gone from weeks to hours for major releases and hours to minutes for patch releases. Better communication of what’s important to users and more time saved for developers. #IstioCon Feature Maturity0 码力 | 18 页 | 199.43 KB | 1 年前3 Set Sail for a
Ship-Shape Istio ReleaseWorking Group - Stability ● Standards and processes ○ Control plane behavior ○ Data plane communication ● Promote revision-based upgrades to stable and support skip-level revision-based upgrades gone from weeks to hours for major releases and hours to minutes for patch releases. Better communication of what’s important to users and more time saved for developers. #IstioCon Feature Maturity0 码力 | 18 页 | 199.43 KB | 1 年前3
 Istio Security Assessmentservice mesh technology stack often used within Kubernetes clusters to provide service-to-service communication, manages TLS certificates, provides workload identity, and includes a builtin authorization system log notes: “Despite the naming, in Istio 1.5 when controlPlaneSecurityEnabled is set to false, communication between the control plane will be secure by default.”1 In the “Default” profile used to represent0 码力 | 51 页 | 849.66 KB | 1 年前3 Istio Security Assessmentservice mesh technology stack often used within Kubernetes clusters to provide service-to-service communication, manages TLS certificates, provides workload identity, and includes a builtin authorization system log notes: “Despite the naming, in Istio 1.5 when controlPlaneSecurityEnabled is set to false, communication between the control plane will be secure by default.”1 In the “Default” profile used to represent0 码力 | 51 页 | 849.66 KB | 1 年前3
 Istio as an API Gateway● Same abstractions for all your traffic control needs ■ Ingress ■ Egress ■ Inter Service Communication ● Build expertise in one discipline ● Decentralized maintenance ● Rich Network functionalities0 码力 | 27 页 | 1.11 MB | 1 年前3 Istio as an API Gateway● Same abstractions for all your traffic control needs ■ Ingress ■ Egress ■ Inter Service Communication ● Build expertise in one discipline ● Decentralized maintenance ● Rich Network functionalities0 码力 | 27 页 | 1.11 MB | 1 年前3
 Apache Kafka with Istio on K8sObservability • Disaster recovery Production grade Apache Kafka on Kubernetes 3 • Secure communication using mTLS between all services • Configurable short-lived certificates • On the fly certificate0 码力 | 14 页 | 875.99 KB | 1 年前3 Apache Kafka with Istio on K8sObservability • Disaster recovery Production grade Apache Kafka on Kubernetes 3 • Secure communication using mTLS between all services • Configurable short-lived certificates • On the fly certificate0 码力 | 14 页 | 875.99 KB | 1 年前3
 Using ECC Workload
Certificates
(pilot-agent environmental variables)● In Istio 1.6, support for workloads to use ECC certificates for mTLS in sidecar-to-sidecar communication was added ○ As of Istio 1.7.7+, 1.8.2+ and 1.9.0+ there is no longer the restriction that a0 码力 | 9 页 | 376.10 KB | 1 年前3 Using ECC Workload
Certificates
(pilot-agent environmental variables)● In Istio 1.6, support for workloads to use ECC certificates for mTLS in sidecar-to-sidecar communication was added ○ As of Istio 1.7.7+, 1.8.2+ and 1.9.0+ there is no longer the restriction that a0 码力 | 9 页 | 376.10 KB | 1 年前3
 宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格Gateway Traffic Flow Cloud Vendor Gateway Consolidation TSB allows service discovery and communication via the NodePort service type instead of a LoadBalancer Architecture ● Multi cluster ● Multi0 码力 | 30 页 | 4.79 MB | 6 月前3 宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格Gateway Traffic Flow Cloud Vendor Gateway Consolidation TSB allows service discovery and communication via the NodePort service type instead of a LoadBalancer Architecture ● Multi cluster ● Multi0 码力 | 30 页 | 4.79 MB | 6 月前3
 Is Your Virtual Machine Really Ready-to-go with Istio?routed through the gateway to the service ● The data plane traffic ■ Single network ● direct communication w/o requiring intermediate Gateway ■ Multiple networks ● all goes though the Gateway ● via0 码力 | 50 页 | 2.19 MB | 1 年前3 Is Your Virtual Machine Really Ready-to-go with Istio?routed through the gateway to the service ● The data plane traffic ■ Single network ● direct communication w/o requiring intermediate Gateway ■ Multiple networks ● all goes though the Gateway ● via0 码力 | 50 页 | 2.19 MB | 1 年前3
 全栈服务网格 - Aeraki 助你在
Istio 服务网格中管理任何七层流量say that we’re running a bookinfo application in an Istio service mesh, but the inter-services communication are done by AwesomePRC, our own RPC protocol, instead of HTTP. So, how could we achieve layer-70 码力 | 29 页 | 2.11 MB | 1 年前3 全栈服务网格 - Aeraki 助你在
Istio 服务网格中管理任何七层流量say that we’re running a bookinfo application in an Istio service mesh, but the inter-services communication are done by AwesomePRC, our own RPC protocol, instead of HTTP. So, how could we achieve layer-70 码力 | 29 页 | 2.11 MB | 1 年前3
 Istio audit report - ADA Logics - 2023-01-30 - v1.0_ = err } resp.Body.Close() break } return nil, nil } 34 Istio Security Audit, 2023 6: Communication between Istio control plane components skips certificate verification Severity: Low Difficulty:0 码力 | 55 页 | 703.94 KB | 1 年前3 Istio audit report - ADA Logics - 2023-01-30 - v1.0_ = err } resp.Body.Close() break } return nil, nil } 34 Istio Security Audit, 2023 6: Communication between Istio control plane components skips certificate verification Severity: Low Difficulty:0 码力 | 55 页 | 703.94 KB | 1 年前3
共 10 条
- 1













