Istio-redirector: the way
to go to manage
thousands of HTTP
redirections#IstioCon Istio-redirector: the way to go to manage thousands of HTTP redirections Etienne Fontaine (@etifontaine) #IstioCon Istio-redirector 301-redirection from /bus/routes/bruxelles/lille0 码力 | 13 页 | 1.07 MB | 1 年前3
Extending service mesh capabilities using a streamlined way based on WASM and ORAS#IstioCon Extending service mesh capabilities using a streamlined way based on WASM and ORAS 王夕宁 | 阿里云服务网格ASM 2 Envoy’s Filter Chain Listener Downstre am Filter Filter Filter Cluster Upstrea0 码力 | 23 页 | 2.67 MB | 1 年前3
Apache Kafka with Istio on K8sToader & Zsolt Varga 2021-Feb-26 Apache Kafka with Istio on K8s 2 • Scalability • Resiliency • Security • Observability • Disaster recovery Production grade Apache Kafka on Kubernetes 3 • Secure client authentication with Istio 12 • Istio provides a security layer for workloads in a uniform way • Envoy WASM filters opens the gates for a whole array of useful features such as Kafka protocol0 码力 | 14 页 | 875.99 KB | 1 年前3
Istio at Scale: How eBay is building a massive Multitenant Service Mesh using IstioDatabases, Key-Value stores - Oracle, MySQL, etc. ○ Big data systems & Pipelines - Hadoop, Apache Spark, Apache Flink, etc. ○ Machine Learning Platforms - Tensorflow, PyTorch, Jupyter Notebook, etc. ○ slow ○ Achieving micro-segmentation at scale ○ Enabling TLS for all applications in a consistent way ● Service Mesh ○ An architectural pattern to implement common Security, Observability, Service Routing0 码力 | 22 页 | 505.96 KB | 1 年前3
Observability and Istio TelemetryObservability And Istio Telemetry 吴 晟 Apache SkyWalking Creator Apache ShardingSphere Co-founder Microsoft MVP Tetrate founding Engineer Bitmain tech expert Service Mesh Meetup #4 上海海站 • ServiceRelation • ServiceInstanceRelation • EndpointRelation • etc. https://github.com/apache/incubator-skywalking/blob/master/docs/en/ concepts-and-designs/oal.md • Extendable Aggregation Five types query • Metadata • Metric • Aggregation • Trace • Alarm https://github.com/apache/incubator- skywalking-query-protocolEcosystem powered by GraphQL and SkyWalking core • Open source0 码力 | 21 页 | 5.29 MB | 6 月前3
宋净超 从开源 Istio 到企业级服务:如何在企业中落地服务网格zero trust multi-cloud conference Best in Class Team ● Creators of the service mesh Istio, gRPC, Apache SkyWalking, Zipkin from Google, Twitter, & VMWare ● Top contributors to Envoy and Istio ● Wrote0 码力 | 30 页 | 4.79 MB | 6 月前3
Envoy原理介绍及线上问题踩坑[2021-03-03T10:32:47.139Z] "POST /v1/xx/xx/xx/xx/xx/983980038/stopxx HTTP/1.1" 503UC"-" "-" 0 95 1 - "10.13.22.7" "Apache- HttpClient/4.5.12 (Java/1.8.0_232)" "U4REJ819523DU961535U8316KUUG2G3X" "10.18.8.13:28443" "10.190 码力 | 30 页 | 2.67 MB | 1 年前3
Istio is a long wild river: how to navigate it safelyKubernetes lacks good control APIs to customize the containers lifecycle in a pod. There is no official way to instruct a pod to: 1. Start the sidecar container first 2. Stop the sidecar container after the recommended if you know what you are doing. Once Kubernetes supports the sidecar pattern in a better way, these workarounds should be deprecated. 21 Shortcoming 2: Autoscaling multi-containers pods Stabilizing performance ○ Reasonable cost Istio proxy performance and capacity Adopting Istio ● Put in another way, know your tradeoffs: ○ How acceptable is the performance loss for the added value? ○ How much should0 码力 | 69 页 | 1.58 MB | 1 年前3
Istio Security Assessmentand test various configurations. These reference architectures were used to provide testers with a way of validating that security expectations in the code were implemented when deployed. Each environment disabled by Istio, so that even when all the security features are enabled, there does not appear to be a way to restrict a Pod’s access to them. Attempts to modify the settings to “controlPlaneAuth Policy: MUTUAL_TLS” services. The current documentation states: “In Istio 1.5, this is no longer the recommended or default way to connect the proxies with the control plane; instead, DNS certificates, which can be signed by Kubernetes0 码力 | 51 页 | 849.66 KB | 1 年前3
Building resilient systems inside the mesh:
abstraction and automation of Virtual Service
generation#IstioCon ● Easy way to manage Virtual Service configs. ● Virtual Service configs become a release artifact. ● Easy abstraction for defining timeouts and retries in a language agnostic way. ● Application0 码力 | 9 页 | 1.04 MB | 1 年前3
共 19 条
- 1
- 2
相关搜索词
IstioredirectorthewaytogomanagethousandsofHTTPredirectionsExtendingservicemeshcapabilitiesusingstreamlinedbasedonWASMandORASApacheKafkawithK8sg2sIstioAtScaleeBaySudhiObservabilityTelemetry宋净超开源企业企业级服务如何落地网格Envoy原理介绍及线问题islongwildriverhownavigateitsafelySecurityAssessmentBuildingresilientsystemsinsideabstractionautomationVirtualServicegeneration













