 Istio Security Assessmenteffect on preventing a Pod not managed by Istio from accessing Istio’s debug interface. Reproduction Steps • Modify the default policy mesh config map for “controlPlaneAuthPolicy: MUTUAL_TLS” • Create a istio of applications from other namespaces that they do not otherwise have any access to. Reproduction Steps 1. Configure a cluster per Appendix E on page 49, with a restricted user confined to a "rest rict-test" in itself is not malicious but could cause a denial-of-service if used repeatedly. Reproduction Steps With the reference cluster setup and replacing PODNAME with a Pod that has curl installed, the following0 码力 | 51 页 | 849.66 KB | 1 年前3 Istio Security Assessmenteffect on preventing a Pod not managed by Istio from accessing Istio’s debug interface. Reproduction Steps • Modify the default policy mesh config map for “controlPlaneAuthPolicy: MUTUAL_TLS” • Create a istio of applications from other namespaces that they do not otherwise have any access to. Reproduction Steps 1. Configure a cluster per Appendix E on page 49, with a restricted user confined to a "rest rict-test" in itself is not malicious but could cause a denial-of-service if used repeatedly. Reproduction Steps With the reference cluster setup and replacing PODNAME with a Pod that has curl installed, the following0 码力 | 51 页 | 849.66 KB | 1 年前3
 Is Your Virtual Machine Really Ready-to-go with Istio?accessible from the VMs ○ (optional) Kubernetes DNS server accessible from the VMs ● Onboard steps ○ Setup Internal Load Balancers (ILBs) for Kube DNS, Pilot, Mixer and CA ○ Generate configs for ● DNS_AUTO_ALLOCATE ○ Decoupled from DNS_CAPTURE ● Documents available ○ Virtual Machine Installation to get started. ○ Virtual Machine Architecture to learn about the high level architecture of0 码力 | 50 页 | 2.19 MB | 1 年前3 Is Your Virtual Machine Really Ready-to-go with Istio?accessible from the VMs ○ (optional) Kubernetes DNS server accessible from the VMs ● Onboard steps ○ Setup Internal Load Balancers (ILBs) for Kube DNS, Pilot, Mixer and CA ○ Generate configs for ● DNS_AUTO_ALLOCATE ○ Decoupled from DNS_CAPTURE ● Documents available ○ Virtual Machine Installation to get started. ○ Virtual Machine Architecture to learn about the high level architecture of0 码力 | 50 页 | 2.19 MB | 1 年前3
 Moving large scale consumer
e-commerce Infrastructure to
Meshas applicable - consul ● Namespace isolation helps reduce Istio proxy resources #IstioCon Next Steps ● Move stateful components in to mesh discovery and routing ● Expose gateway services via Istio0 码力 | 14 页 | 1.76 MB | 1 年前3 Moving large scale consumer
e-commerce Infrastructure to
Meshas applicable - consul ● Namespace isolation helps reduce Istio proxy resources #IstioCon Next Steps ● Move stateful components in to mesh discovery and routing ● Expose gateway services via Istio0 码力 | 14 页 | 1.76 MB | 1 年前3
 Your laptop as part
of the service meshcost-effective #IstioCon 1. Minimize time to bug detection Dev -> PR -> master -> QA -> prod 3 steps away to find a problem #IstioCon 2. Allow simultaneous tests Only one commit at a time from your0 码力 | 30 页 | 555.24 KB | 1 年前3 Your laptop as part
of the service meshcost-effective #IstioCon 1. Minimize time to bug detection Dev -> PR -> master -> QA -> prod 3 steps away to find a problem #IstioCon 2. Allow simultaneous tests Only one commit at a time from your0 码力 | 30 页 | 555.24 KB | 1 年前3
 SberBank story:
moving Istio from PoC to productionenvironment aren’t a waste of time 1. Istio Discovery Restarts (#25495) 2. Proxy Probes (#26792) Further Steps • Multi-cluster Discovery for OCP & Kubernetes • Multi-cluster Service Topology • Cloud-Native0 码力 | 14 页 | 1.68 MB | 1 年前3 SberBank story:
moving Istio from PoC to productionenvironment aren’t a waste of time 1. Istio Discovery Restarts (#25495) 2. Proxy Probes (#26792) Further Steps • Multi-cluster Discovery for OCP & Kubernetes • Multi-cluster Service Topology • Cloud-Native0 码力 | 14 页 | 1.68 MB | 1 年前3
 Istio Service Mesh at Enterprise ScaleMulti-region deployments ● Non-flat networks ● Multi-tenant configuration ● Management of Istio installation ● Self-service mesh enablement for service owners Demo Admiral API Gateway Payments0 码力 | 12 页 | 1.23 MB | 1 年前3 Istio Service Mesh at Enterprise ScaleMulti-region deployments ● Non-flat networks ● Multi-tenant configuration ● Management of Istio installation ● Self-service mesh enablement for service owners Demo Admiral API Gateway Payments0 码力 | 12 页 | 1.23 MB | 1 年前3
 Istio Project Update#IstioCon 2018-2019: Year of Service Mesh #IstioCon 2020: Year of Istio Innovation Simplified installation Simplified control plane New extension Model Unified multicluster model Simplified VM onboarding0 码力 | 22 页 | 1.10 MB | 1 年前3 Istio Project Update#IstioCon 2018-2019: Year of Service Mesh #IstioCon 2020: Year of Istio Innovation Simplified installation Simplified control plane New extension Model Unified multicluster model Simplified VM onboarding0 码力 | 22 页 | 1.10 MB | 1 年前3
 Using ECC Workload
Certificates
(pilot-agent environmental variables)ECDSA for use by pilot-agent ○ For gateways this environmental variable also must be set on installation/upgrade #IstioCon istioctl iop.yaml Install with istioctl install -f iop.yaml apiVersion:0 码力 | 9 页 | 376.10 KB | 1 年前3 Using ECC Workload
Certificates
(pilot-agent environmental variables)ECDSA for use by pilot-agent ○ For gateways this environmental variable also must be set on installation/upgrade #IstioCon istioctl iop.yaml Install with istioctl install -f iop.yaml apiVersion:0 码力 | 9 页 | 376.10 KB | 1 年前3
 Istio audit report - ADA Logics - 2023-01-30 - v1.0requires no network access: “The build service… MUST prevent network access while running the build steps.” With regards to reproducibility of builds, Ada Logics did not find evidence of any declaration0 码力 | 55 页 | 703.94 KB | 1 年前3 Istio audit report - ADA Logics - 2023-01-30 - v1.0requires no network access: “The build service… MUST prevent network access while running the build steps.” With regards to reproducibility of builds, Ada Logics did not find evidence of any declaration0 码力 | 55 页 | 703.94 KB | 1 年前3
共 9 条
- 1













