Istio Meetup China 服务网格安全 理解 Istio CNIcontainer in workload Istiod watch updates & start networking sidecar proxy init container update iptable rule for proxy terminate init container Start workload with updated ip routing rules Networking lifecycle Kubelet invoke CNI plugins CNI plugins setup ip for pod Istio CNI install isidecar network routing rule to workload iptable Benefits of Istio CNI No need for CAP_NET_ADMIN and CAP_NET_RAW permission No in here and bypassing istio sidecar proxy(race condition) Istio CNI install sidecar network routing rule to workload iptable Issue in Istio CNI Kubelet Start a pausing pod Kubelet invoke CNI plugins CNI0 码力 | 19 页 | 3.17 MB | 1 年前3
Secure your microservices with istio step by stepmatchLabels: app: reviews mtls: mode: STRICT 1) Apply destination rule to enable client side mTLS mTLS in Istio - Destination rule Using ingress port and ingress host to send request: can access reviews-v1 ISTIO_MUTUAL mode on client side Access productpage 1) Apply destination rule enable client side mTLS mTLS in Istio - Destination rule http http http http mTLS mTLS #IstioCon mTLS in Istio - DestinationRule0 码力 | 34 页 | 67.93 MB | 1 年前3
Building resilient systems inside the mesh:
abstraction and automation of Virtual Service
generationand allows for creation of miscellaneous rules Misc please rule for autogeneration K8s Greeter service example #IstioCon Building the new rule #IstioCon Deploying to a cluster #IstioCon ● Easy way0 码力 | 9 页 | 1.04 MB | 1 年前3
Leveraging Istio for Creating API Tests - Low Effort API Testing for MicroservicesQA trace: r trace: r trace: r trace: r CI Pipeline | CONFIDENTIAL 16 ML-assisted Context Rule Learning createProduct(…): Response { “productId”: “HDSN1890675”, “src”: “Canada” : } Supervised system to accept true positives • No code! | CONFIDENTIAL 17 ML-assisted Assertion Rule Learning createOrder Response: Recording { “orderId”: “ORDR1890675”, “orderValue”: “58.75”0 码力 | 21 页 | 1.09 MB | 1 年前3
Is Your Virtual Machine Really Ready-to-go with Istio?bootstrap certificate on the VM ■ Dependency on K8s API server ■ Requires creating an RBAC impersonation rule for each user ■ Private key and CSR generation limited to Istio agent (no support of other provisioner performance) ● Offload ○ Traffic management ○ Security (DDoS defense…) ● HW acceleration ○ Crypto ○ Rule matching ● Further isolation w/ host ● CapEx, OpEx #IstioCon RDMA (Remote Direct Memory Access)0 码力 | 50 页 | 2.19 MB | 1 年前3
Istio Service Mesh at Enterprise Scale“service’s” hostname ● Validated ○ Deployments ○ Virtual Service ○ Service Entry ○ Destination Rule ● Blocked ○ Envoy Filters ○ Gateways Developer Platform Integration ● Mesh Automation ○ Control0 码力 | 12 页 | 1.23 MB | 1 年前3
Moving large scale consumer
e-commerce Infrastructure to
Meshcreation or updation ● Templatise the Kubernetes deployment including Virtual Service and Destination rule #IstioCon Takeaways ● Identify the problems and improvements ● POCs for all known use-cases and0 码力 | 14 页 | 1.76 MB | 1 年前3
Observability and Istio TelemetryINDICATOR All metric data belong to this. They are in min/ hour/day/hour time level. They are named by Rule: scopename_funcName_timeLevel RECORD Segment and AlarmRecord belong to this type.Query in GraphQL0 码力 | 21 页 | 5.29 MB | 6 月前3
Optimal Canary Deployments using
Istio and how it scores over Spring
Cloud and KubernetesHeader: X-User-Type: Admin Header: X-User-Type: Non-Admin Header: X-User-Type: Admin Destination Rule:0 码力 | 9 页 | 1011.00 KB | 1 年前3
Preserve Original Source
Address within Istio--nfmask 0xffffffff -- ctmask 0xffffffff # packet sent back to envoy will be marked 1337 ip -f inet rule add fwmark 1337 lookup 133 ip -f inet route add local default dev lo table 133 ③ echo 1 > /proc0 码力 | 29 页 | 713.08 KB | 1 年前3
共 15 条
- 1
- 2
相关搜索词
IstioMeetupChina服务网格安全理解CNISecureyourmicroserviceswithistiostepbyBuildingresilientsystemsinsidethemeshabstractionandautomationofVirtualServicegenerationLeveragingforCreatingAPITestsLowEffortTestingMicroservicesMeshatEnterpriseScaleMovinglargescaleconsumercommerceInfrastructuretoObservabilityTelemetryOptimalCanaryDeploymentsusinghowitscoresoverSpringCloudKubernetesPreserveOriginalSourceAddresswithin













